// MITRE ATT&CK

T1564.003 · Hidden Window

🎯 Stealth LinuxmacOSWindows Sub-technique

Sub-technique of T1564 · Hide Artifacts.

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environment...

How to detect & mitigate it

Detecting Hidden Window starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.