Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository. Shared memory directories on Linux systems (`/dev/shm`, `/run/shm`, `/var/run`, and `/var/lock`) and volatile directories on Network Devices (`/tmp` and `/volatile`) may also be considered fileless storage, as files written to these directories are mapped directly to RAM and not stored on the disk..
Similar to fileless in-memory behaviors such as Reflective Code Loading and Process Injection, fileless data storage may remain undetected by antivirus and other endpoint security tools that can only access specific file formats from disk storage. Leveraging fileless storage may also allow adversaries to bypass the protections offered by read-only file systems in Linux.
Adversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of Persistence) and collected data not yet exfiltrated from the victim (e.g., Local Data Staging). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored.
Some forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., `%SystemRoot%\System32\Wbem\Repository`) or Registry (e.g., `%SystemRoot%\System32\Config`) physical files.
Rules on DetectionCode tagged with T1027.011.
| Rule | Level | Log source |
|---|---|---|
| Process Execution From Shared Memory Directory | high | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| PowerShell WebRequest Using Memory Stream | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Njrat Fileless Storage via Registry | TTP | NULL | Sysmon EventID 13 |
| Windows Registry Payload Injection | TTP | NULL | Sysmon EventID 13 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32's backdoor has stored its configuration in a registry key. |
| GroupTurla | Turla has used the Registry to store encrypted and encoded payloads. |
| Used by | Procedure example |
|---|---|
| MalwareChaes | Some versions of Chaes stored its instructions (otherwise in a `instructions.ini` file) in the Registry. |
| MalwareCHOPSTICK | CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry. |
| MalwareComRAT | ComRAT has stored encrypted orchestrator code and payloads in the Registry. |
| MalwareDarkWatchman | DarkWatchman can store configuration strings, keylogger, and output of components in the Registry. |
| MalwareExaramel for Windows | Exaramel for Windows stores the backdoor's configuration in the Registry in XML format. |
| MalwareGelsemium | Gelsemium can store its components in the Registry. |
| MalwareGrandoreiro | Grandoreiro can store its configuration in the Registry at `HKCU\Software\` under frequently changing names including |
| MalwareMosquito | Mosquito stores configuration values under the Registry key |
| Used by | Procedure example |
|---|---|
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs. |
| CampaignQuad7 Activity | Quad7 Activity has infected victim network devices by storing artifacts in the |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.