// MITRE ATT&CK

T1564.011 · Ignore Process Interrupts

🎯 Stealth LinuxmacOSWindows Sub-technique

Sub-technique of T1564 · Hide Artifacts.

Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many operating systems use signals to deliver messages to control process behavior. Command interpreters often include specific commands/flags that ignore errors and other hangups, such as when...

How to detect & mitigate it

Detecting Ignore Process Interrupts starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.