Technique with 14 sub-techniques.View on attack.mitre.org
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.
Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.
Rules on DetectionCode tagged with T1564 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Disable Show Hidden Files | Anomaly | NULL | Sysmon EventID 13 | T1564.001 |
| Headless Browser Mockbin or Mocky Request | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564.003 |
| Headless Browser Usage | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564.003 |
| MacOS Hidden Files and Directories | Anomaly | NULL | Osquery Results | T1564.001 |
| O365 BEC Email Hiding Rule Created | TTP | NULL | T1564.008 | |
| O365 Email New Inbox Rule Created | Anomaly | NULL | Office 365 Universal Audit Log | T1564.008 |
| O365 Email Transport Rule Changed | Anomaly | NULL | Office 365 Universal Audit Log | T1564.008 |
| Reg exe used to hide files directories via registry keys | TTP | NULL | Sysmon EventID 1 | T1564.001 |
| Windows Alternate Data Stream Created Over Local Share | Anomaly | NULL | Windows Event Log Security 5145 | T1564.004 |
| Windows Alternate DataStream - Base64 Content | TTP | NULL | Sysmon EventID 15 | T1564.004 |
| Windows Alternate DataStream - Executable Content | TTP | NULL | Sysmon EventID 15 | T1564.004 |
| Windows Alternate DataStream - Process Execution | TTP | NULL | Windows Event Log Security 4688, Sysmon EventID 1 | T1564.004 |
| Windows ConHost with Headless Argument | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564.003 T1564.006 |
| Windows New Deny Permission Set On Service SD Via Sc.EXE | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564 |
| Windows New Service Security Descriptor Set Via Sc.EXE | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564 |
| Windows Suspicious QEMU Execution | TTP | NULL | Sysmon EventID 1 | T1564.006 |
| Windows SymbolicLink-Testing-Tools Utility Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1564.004 |
| Windows Wermgr Alternate Data Stream in Temp Dir | Anomaly | NULL | Sysmon EventID 15 | T1564.004 |
| ID | Name | Examples |
|---|---|---|
| T1564.001 | Hidden Files and Directories | 60 |
| T1564.002 | Hidden Users | 3 |
| T1564.003 | Hidden Window | 61 |
| T1564.004 | NTFS File Attributes | 16 |
| T1564.005 | Hidden File System | 6 |
| T1564.006 | Run Virtual Instance | 3 |
| T1564.007 | VBA Stomping | 0 |
| T1564.008 | Email Hiding Rules | 3 |
| T1564.009 | Resource Forking | 2 |
| T1564.010 | Process Argument Spoofing | 2 |
| T1564.011 | Ignore Process Interrupts | 9 |
| T1564.012 | File/Path Exclusions | 1 |
| T1564.013 | Bind Mounts | 1 |
| T1564.014 | Extended Attributes | 0 |
None recorded.
None recorded.
| Used by | Procedure example |
|---|---|
| MalwareBundlore | Bundlore uses the |
| MalwareDarkTortilla | DarkTortilla has used `%HiddenReg%` and `%HiddenKey%` as part of its persistence via the Windows registry. |
| MalwareNOOPLDR | NOOPLDR can hide services used to aid execution. |
| MalwareOSX/Shlayer | OSX/Shlayer has used the |
| ToolRemcos | Remcos can modify file attributes to hide the file. |
| MalwareTarrask | Tarrask is able to create “hidden” scheduled tasks by deleting the Security Descriptor (`SD`) registry value. |
| MalwareWarzoneRAT | WarzoneRAT can masquerade the Process Environment Block on a compromised host to hide its attempts to elevate privileges through `IFileOperation`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.