// MITRE ATT&CK
T1564 · Hide Artifacts
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing fi...
How to detect & mitigate it
Detecting Hide Artifacts starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (14)
T1564.001
Hidden Files and Directories T1564.002
Hidden Users T1564.003
Hidden Window T1564.004
NTFS File Attributes T1564.005
Hidden File System T1564.006
Run Virtual Instance T1564.007
VBA Stomping T1564.008
Email Hiding Rules T1564.009
Resource Forking T1564.010
Process Argument Spoofing T1564.011
Ignore Process Interrupts T1564.012
File/Path Exclusions T1564.013
Bind Mounts T1564.014
Extended Attributes
Hidden Files and Directories T1564.002
Hidden Users T1564.003
Hidden Window T1564.004
NTFS File Attributes T1564.005
Hidden File System T1564.006
Run Virtual Instance T1564.007
VBA Stomping T1564.008
Email Hiding Rules T1564.009
Resource Forking T1564.010
Process Argument Spoofing T1564.011
Ignore Process Interrupts T1564.012
File/Path Exclusions T1564.013
Bind Mounts T1564.014
Extended Attributes
Related techniques
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.