File/Path Exclusions

T1564.012

Sub-technique of T1564 Hide Artifacts.View on attack.mitre.org

About this technique

Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities. AV and other file-based scanners often include exclusions to optimize performance as well as ease installation and legitimate use of applications. These exclusions may be contextual (e.g., scans are only initiated in response to specific triggering events/alerts), but are also often hardcoded strings referencing specific folders and/or files assumed to be trusted and legitimate.

Adversaries may abuse these exclusions to hide their file-based artifacts. For example, rather than tampering with tool settings to add a new exclusion (i.e., Disable or Modify Tools), adversaries may drop their file-based payloads in default or otherwise well-known exclusions. Adversaries may also use Security Software Discovery and other Discovery/Reconnaissance activities to both discover and verify existing exclusions in a victim environment.

Detection rules0

Rules on DetectionCode tagged with T1564.012.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples1

Groups1

Used byProcedure example
GroupTurla

Turla has placed LunarWeb install files into directories that are excluded from scanning.

References1

  1. Microsoft File Folder Exclusions Open source
    Microsoft. (2024, February 27). Contextual file and folder exclusions. Retrieved March 29, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.