Hide Artifacts

T1564

Technique with 14 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.

Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.

Detection rules71

Rules on DetectionCode tagged with T1564 or one of its sub-techniques.

Sigma53

RuleLevelLog sourceTechnique
Exports Registry Key To an Alternate Data Streamhighwindows / create_stream_hashT1564.004
File Download with Headless Browserhighwindows / process_creationT1564.003
HackTool - Covenant PowerShell Launcherhighwindows / process_creationT1564.003
HackTool Named File Stream Createdhighwindows / create_stream_hashT1564.004
Hiding User Account Via SpecialAccounts Registry Keyhighwindows / registry_setT1564.002
NTFS Alternate Data Streamhighwindows / ps_scriptT1564.004
Potential Data Stealing Via Chromium Headless Debugginghighwindows / process_creationT1564.003
Potential Rundll32 Execution With DLL Stored In ADShighwindows / process_creationT1564.004
Potentially Suspicious Execution From Parent Process In Public Folderhighwindows / process_creationT1564
PowerShell Logging Disabled Via Registry Key Tamperinghighwindows / registry_setT1564.001
PrintBrm ZIP Creation of Extractionhighwindows / process_creationT1564.004
Registry Persistence via Service in Safe Modehighwindows / registry_setT1564.001
Run PowerShell Script from ADShighwindows / process_creationT1564.004
Set Suspicious Files as System Files Using Attrib.EXEhighwindows / process_creationT1564.001
Suspicious Creation with Colorcplhighwindows / file_eventT1564

Splunk18

RuleTypeRiskData sourceTechnique
Disable Show Hidden FilesAnomalyNULLSysmon EventID 13T1564.001
Headless Browser Mockbin or Mocky RequestTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1564.003
Headless Browser UsageAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1564.003
MacOS Hidden Files and DirectoriesAnomalyNULLOsquery ResultsT1564.001
O365 BEC Email Hiding Rule CreatedTTPNULLT1564.008
O365 Email New Inbox Rule CreatedAnomalyNULLOffice 365 Universal Audit LogT1564.008
O365 Email Transport Rule ChangedAnomalyNULLOffice 365 Universal Audit LogT1564.008
Reg exe used to hide files directories via registry keysTTPNULLSysmon EventID 1T1564.001
Windows Alternate Data Stream Created Over Local ShareAnomalyNULLWindows Event Log Security 5145T1564.004
Windows Alternate DataStream - Base64 ContentTTPNULLSysmon EventID 15T1564.004
Windows Alternate DataStream - Executable ContentTTPNULLSysmon EventID 15T1564.004
Windows Alternate DataStream - Process ExecutionTTPNULLWindows Event Log Security 4688, Sysmon EventID 1T1564.004
Windows ConHost with Headless ArgumentTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1564.003 T1564.006
Windows New Deny Permission Set On Service SD Via Sc.EXEAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1564
Windows New Service Security Descriptor Set Via Sc.EXEAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1564

Sub-techniques14

IDNameExamples
T1564.001Hidden Files and Directories60
T1564.002Hidden Users3
T1564.003Hidden Window61
T1564.004NTFS File Attributes16
T1564.005Hidden File System6
T1564.006Run Virtual Instance3
T1564.007VBA Stomping0
T1564.008Email Hiding Rules3
T1564.009Resource Forking2
T1564.010Process Argument Spoofing2
T1564.011Ignore Process Interrupts9
T1564.012File/Path Exclusions1
T1564.013Bind Mounts1
T1564.014Extended Attributes0

Groups0

None recorded.

Software7

Campaigns0

None recorded.

Procedure examples7

Software7

Used byProcedure example
MalwareBundlore

Bundlore uses the mktemp utility to make unique file and directory names for payloads, such as TMP_DIR=`mktemp -d -t x.

MalwareDarkTortilla

DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry.

MalwareNOOPLDR

NOOPLDR can hide services used to aid execution.

MalwareOSX/Shlayer

OSX/Shlayer has used the mktemp utility to make random and unique filenames for payloads, such as export tmpDir="$(mktemp -d /tmp/XXXXXXXXXXXX)" or mktemp -t Installer.

ToolRemcos

Remcos can modify file attributes to hide the file.

MalwareTarrask

Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value.

MalwareWarzoneRAT

WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`.

References4

  1. Cybereason OSX Pirrit Open source
    Amit Serper. (2016). Cybereason Lab Analysis OSX.Pirrit. Retrieved December 10, 2021.
  2. MalwareBytes ADS July 2015 Open source
    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.
  3. Sofacy Komplex Trojan Open source
    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.
  4. Sophos Ragnar May 2020 Open source
    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.