// MITRE ATT&CK
T1564.012 · File/Path Exclusions
Sub-technique of T1564 · Hide Artifacts.
Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities. AV and other file-based scanners often include exclusions to optimize performance as well as ease installation and legi...
How to detect & mitigate it
Detecting File/Path Exclusions starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable T1006
Direct Volume Access
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable T1006
Direct Volume Access
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.