// MITRE ATT&CK
T1564.012 · File/Path Exclusions
Sub-técnica de T1564 · Hide Artifacts.
Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities. AV and other file-based scanners often include exclusions to optimize performance as well as ease installation and legi...
¿Cómo detectarlo y mitigarlo?
La detección de File/Path Exclusions parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Técnicas relacionadas
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable T1006
Direct Volume Access
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable T1006
Direct Volume Access
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.