// MITRE ATT&CK
T1564 · Hide Artifacts
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing fi...
¿Cómo detectarlo y mitigarlo?
La detección de Hide Artifacts parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (14)
T1564.001
Hidden Files and Directories T1564.002
Hidden Users T1564.003
Hidden Window T1564.004
NTFS File Attributes T1564.005
Hidden File System T1564.006
Run Virtual Instance T1564.007
VBA Stomping T1564.008
Email Hiding Rules T1564.009
Resource Forking T1564.010
Process Argument Spoofing T1564.011
Ignore Process Interrupts T1564.012
File/Path Exclusions T1564.013
Bind Mounts T1564.014
Extended Attributes
Hidden Files and Directories T1564.002
Hidden Users T1564.003
Hidden Window T1564.004
NTFS File Attributes T1564.005
Hidden File System T1564.006
Run Virtual Instance T1564.007
VBA Stomping T1564.008
Email Hiding Rules T1564.009
Resource Forking T1564.010
Process Argument Spoofing T1564.011
Ignore Process Interrupts T1564.012
File/Path Exclusions T1564.013
Bind Mounts T1564.014
Extended Attributes
Técnicas relacionadas
T1055.011
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Extra Window Memory Injection T1205.002
Socket Filters T1027.011
Fileless Storage T1218.011
Rundll32 T1027.009
Embedded Payloads T1564.012
File/Path Exclusions T1216.001
PubPrn T1574.007
Path Interception by PATH Environment Variable
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.