MITRE ATT&CK technique
Data Obfuscation detection rulesT1001
Data Obfuscation (T1001) is a MITRE ATT&CK technique in the Command and Control tactic. This page lists the 2 community-maintained Sigma detection rules in the library mapped to T1001 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows.
T1001 on attack.mitre.org2 rules
Top products
Tactic
Suspicious LDAP-Attributes Used
highDetects the usage of particular AttributeLDAPDisplayNames, which are known for data exchange via LDAP by the tool LDAPFragger and are additionally not commonly used in companies.
windows
ADSI-Cache File Creation By Uncommon Tool
mediumDetects the creation of an "Active Directory Schema Cache File" (.sch) file by an uncommon tool.
windows · file_event