MITRE ATT&CK technique
Obfuscated Files or Information detection rulesT1027
Obfuscated Files or Information (T1027) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 125 community-maintained Sigma detection rules in the library mapped to T1027 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, macos.
Top products
Tactic
Turla Group Commands May 2020
criticalDetects commands used by Turla group as reported by ESET in May 2020
windows · process_creation
Base64 Encoded PowerShell Command Detected
highDetects usage of the "FromBase64String" function in the commandline which is used to decode a base64 encoded string
windows · process_creation
Binary Padding - Linux
highAdversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.
linux
Binary Padding - MacOS
highAdversaries may use binary padding to add junk data and change the on-disk representation of malware. This rule detect using dd and truncate to add a junk data to file.
macos · process_creation
Csc.EXE Execution Form Potentially Suspicious Parent
highDetects a potentially suspicious parent of "csc.exe", which could be a sign of payload delivery.
windows · process_creation
File Decoded From Base64/Hex Via Certutil.EXE
highDetects the execution of certutil with either the "decode" or "decodehex" flags to decode base64 or hex encoded files. This can be abused by attackers to decode an encoded payload before execution
windows · process_creation
File In Suspicious Location Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the files are located in potentially suspicious locations
windows · process_creation
HackTool - CrackMapExec PowerShell Obfuscation
highThe CrachMapExec pentesting framework implements a PowerShell obfuscation with some static strings detected by this rule.
windows · process_creation
Invoke-Obfuscation CLIP+ Launcher
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · process_creation
Invoke-Obfuscation CLIP+ Launcher - PowerShell
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · ps_script
Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows · ps_module
Invoke-Obfuscation CLIP+ Launcher - Security
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows
Invoke-Obfuscation CLIP+ Launcher - System
highDetects Obfuscated use of Clip.exe to execute PowerShell
windows
Invoke-Obfuscation Obfuscated IEX Invocation
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block
windows · process_creation
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the following code block \u2014
windows · ps_script
Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block cited in the reference section below
windows · ps_module
Invoke-Obfuscation Obfuscated IEX Invocation - Security
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references
windows
Invoke-Obfuscation Obfuscated IEX Invocation - System
highDetects all variations of obfuscated powershell IEX invocation code generated by Invoke-Obfuscation framework from the code block linked in the references
windows
Invoke-Obfuscation STDIN+ Launcher
highDetects Obfuscated use of stdin to execute PowerShell
windows · process_creation
Invoke-Obfuscation STDIN+ Launcher - Powershell
highDetects Obfuscated use of stdin to execute PowerShell
windows · ps_script
Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
highDetects Obfuscated use of stdin to execute PowerShell
windows · ps_module
Invoke-Obfuscation STDIN+ Launcher - Security
highDetects Obfuscated use of stdin to execute PowerShell
windows
Invoke-Obfuscation STDIN+ Launcher - System
highDetects Obfuscated use of stdin to execute PowerShell
windows
Invoke-Obfuscation VAR+ Launcher
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · process_creation
Invoke-Obfuscation VAR+ Launcher - PowerShell
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · ps_script
Invoke-Obfuscation VAR+ Launcher - PowerShell Module
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows · ps_module
Invoke-Obfuscation VAR+ Launcher - Security
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows
Invoke-Obfuscation VAR+ Launcher - System
highDetects Obfuscated use of Environment Variables to execute PowerShell
windows
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · process_creation
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · ps_script
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows · ps_module
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows
Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
highDetects Obfuscated Powershell via VAR++ LAUNCHER
windows
Invoke-Obfuscation Via Stdin
highDetects Obfuscated Powershell via Stdin in Scripts
windows · process_creation
Invoke-Obfuscation Via Stdin - Powershell
highDetects Obfuscated Powershell via Stdin in Scripts
windows · ps_script
Invoke-Obfuscation Via Stdin - PowerShell Module
highDetects Obfuscated Powershell via Stdin in Scripts
windows · ps_module
Invoke-Obfuscation Via Stdin - Security
highDetects Obfuscated Powershell via Stdin in Scripts
windows
Invoke-Obfuscation Via Stdin - System
highDetects Obfuscated Powershell via Stdin in Scripts
windows
Invoke-Obfuscation Via Use Clip
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · process_creation
Invoke-Obfuscation Via Use Clip - Powershell
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · ps_script
Invoke-Obfuscation Via Use Clip - PowerShell Module
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows · ps_module
Invoke-Obfuscation Via Use Clip - Security
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows
Invoke-Obfuscation Via Use Clip - System
highDetects Obfuscated Powershell via use Clip.exe in Scripts
windows
Invoke-Obfuscation Via Use MSHTA
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · process_creation
Invoke-Obfuscation Via Use MSHTA - PowerShell
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · ps_script
Invoke-Obfuscation Via Use MSHTA - PowerShell Module
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows · ps_module
Invoke-Obfuscation Via Use MSHTA - Security
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows
Invoke-Obfuscation Via Use MSHTA - System
highDetects Obfuscated Powershell via use MSHTA in Scripts
windows
Invoke-Obfuscation Via Use Rundll32 - PowerShell
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · ps_script
Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows · ps_module
Invoke-Obfuscation Via Use Rundll32 - Security
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows
Invoke-Obfuscation Via Use Rundll32 - System
highDetects Obfuscated Powershell via use Rundll32 in Scripts
windows
Obfuscated PowerShell MSI Install via WindowsInstaller COM
highDetects the execution of obfuscated PowerShell commands that attempt to install MSI packages via the Windows Installer COM object (`WindowsInstaller.Installer`). The technique involves manipulating strings to hide functionality, such as constructing class names using string insertion (e.g., 'indowsInstaller.Installer'.Insert(0,'W')) and correcting malformed URLs (e.g., converting 'htps://' to 'https://') at runtime. This behavior is commonly associated with malware loaders or droppers that aim to bypass static detection by hiding intent in runtime-generated strings and using legitimate tools for code execution. The use of `InstallProduct` and COM object creation, particularly combined with hidden window execution and suppressed UI, indicates an attempt to install software (likely malicious) without user interaction.
windows · process_creation
Operation Wocao Activity
highDetects activity mentioned in Operation Wocao report
windows · process_creation
Operation Wocao Activity - Security
highDetects activity mentioned in Operation Wocao report
windows
Password Protected ZIP File Opened (Email Attachment)
highDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows
Password Protected ZIP File Opened (Suspicious Filenames)
highDetects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.
windows
Ping Hex IP
highDetects a ping command that uses a hex encoded IP address
windows · process_creation
Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
highDetects potential commandline obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows · process_creation
Potential Emotet Activity
highDetects all Emotet like process executions that are not covered by the more generic rules
windows · process_creation
Potential PowerShell Command Line Obfuscation
highDetects the PowerShell command lines with special characters
windows · process_creation
Potential PowerShell Obfuscation Via Reversed Commands
highDetects the presence of reversed PowerShell commands in the CommandLine. This is often used as a method of obfuscation by attackers
windows · process_creation
Potential PowerShell Obfuscation Via WCHAR/CHAR
highDetects suspicious encoded character syntax often used for defense evasion
windows · process_creation
Potential Winnti Dropper Activity
highDetects files dropped by Winnti as described in RedMimicry Winnti playbook
windows · file_event
PowerShell Base64 Encoded Invoke Keyword
highDetects UTF-8 and UTF-16 Base64 encoded powershell 'Invoke-' calls
windows · process_creation
PowerShell Base64 Encoded Reflective Assembly Load
highDetects base64 encoded .NET reflective loading of Assembly
windows · process_creation
PowerShell Base64 Encoded WMI Classes
highDetects calls to base64 encoded WMI class such as "Win32_ShadowCopy", "Win32_ScheduledJob", etc.
windows · process_creation
Powershell Token Obfuscation - Process Creation
highDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation
windows · process_creation
Process Execution From Shared Memory Directory
highDetects the execution of a binary from the Linux shared memory directory /dev/shm. This directory is a tmpfs mount backed entirely by RAM and is abused by attackers for fileless malware staging because files written there never touch physical disk and may evade disk-based detection.
linux · process_creation
PUA - DefenderCheck Execution
highDetects the use of DefenderCheck, a tool to evaluate the signatures used in Microsoft Defender. It can be used to figure out the strings / byte chains used in Microsoft Defender to detect a tool and thus used for AV evasion.
windows · process_creation
Python One-Liners with Base64 Decoding
highDetects Python one-liners that use base64 decoding functions in command line executions. Malicious scripts or attackers often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
windows · process_creation
Python One-Liners with Base64 Decoding - Linux
highDetects the use of Python's base64 decoding functions in command line executions on Linux systems. Malicious scripts often use python one-liners to decode and execute base64-encoded payloads, which is a common technique for obfuscation and evasion.
linux · process_creation
Renamed AutoIt Execution
highDetects the execution of a renamed AutoIt2.exe or AutoIt3.exe. AutoIt is a scripting language and automation tool for Windows systems. While primarily used for legitimate automation tasks, it can be misused in cyber attacks. Attackers can leverage AutoIt to create and distribute malware, including keyloggers, spyware, and botnets. A renamed AutoIt executable is particularly suspicious.
windows · process_creation
Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
highDetects suspicious base64 encoded and obfuscated "LOAD" keyword used in .NET "reflection.assembly"
windows · process_creation
Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
highDetects process creation with suspicious whitespace padding followed by a '#' character, which may indicate ClickFix or FileFix techniques used to conceal malicious commands from visual inspection. ClickFix and FileFix are social engineering attack techniques where adversaries distribute phishing documents or malicious links that deceive users into opening the Windows Run dialog box or File Explorer search bar. The victims are then instructed to paste commands from their clipboard, which contain extensive whitespace padding using various Unicode space characters to push the actual malicious command far to the right, effectively hiding it from immediate view.
windows · process_creation
Suspicious File Downloaded From Direct IP Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from direct IPs.
windows · process_creation
Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
highDetects the execution of certutil with certain flags that allow the utility to download files from file-sharing websites.
windows · process_creation
Suspicious File Encoded To Base64 Via Certutil.EXE
highDetects the execution of certutil with the "encode" flag to encode a file to base64 where the extensions of the file is suspicious
windows · process_creation
Suspicious Filename with Embedded Base64 Commands
highDetects files with specially crafted filenames that embed Base64-encoded bash payloads designed to execute when processed by shell scripts. These filenames exploit shell interpretation quirks to trigger hidden commands, a technique observed in VShell malware campaigns.
linux · file_event
Suspicious Get-Variable.exe Creation
highGet-Variable is a valid PowerShell cmdlet WindowsApps is by default in the path where PowerShell is executed. So when the Get-Variable command is issued on PowerShell execution, the system first looks for the Get-Variable executable in the path and executes the malicious binary instead of looking for the PowerShell cmdlet.
windows · file_event
Suspicious Space Characters in RunMRU Registry Path - ClickFix
highDetects the occurrence of numerous space characters in RunMRU registry paths, which may indicate execution via phishing lures using clickfix techniques to hide malicious commands in the Windows Run dialog box from naked eyes.
windows · registry_set
Suspicious Space Characters in TypedPaths Registry Path - FileFix
highDetects the occurrence of numerous space characters in TypedPaths registry paths, which may indicate execution via phishing lures using file-fix techniques to hide malicious commands.
windows · registry_set
Suspicious SYSTEM User Process Creation
highDetects a suspicious process creation as SYSTEM user (suspicious program or command line parameter)
windows · process_creation
Visual Basic Command Line Compiler Usage
highDetects successful code compilation via Visual Basic Command Line Compiler that utilizes Windows Resource to Object Converter.
windows · process_creation
Certificate Exported Via Certutil.EXE
mediumDetects the execution of the certutil with the "exportPFX" flag which allows the utility to export certificates.
windows · process_creation
ConvertTo-SecureString Cmdlet Usage Via CommandLine
mediumDetects usage of the "ConvertTo-SecureString" cmdlet via the commandline. Which is fairly uncommon and could indicate potential suspicious activity
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
Dynamic .NET Compilation Via Csc.EXE - Hunting
mediumDetects execution of "csc.exe" to compile .NET code. Attackers often leverage this to compile code on the fly and use it in other stages.
windows · process_creation
File Encoded To Base64 Via Certutil.EXE
mediumDetects the execution of certutil with the "encode" flag to encode a file to base64. This can be abused by threat actors and attackers for data exfiltration
windows · process_creation
Findstr Launching .lnk File
mediumDetects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
windows · process_creation
Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the invocation of PowerShell commands with references to classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · process_creation
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_script
Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows · ps_module
Invoke-Obfuscation COMPRESS OBFUSCATION - Security
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows
Invoke-Obfuscation COMPRESS OBFUSCATION - System
mediumDetects Obfuscated Powershell via COMPRESS OBFUSCATION
windows
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_script
Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows · ps_module
Invoke-Obfuscation RUNDLL LAUNCHER - Security
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows
Invoke-Obfuscation RUNDLL LAUNCHER - System
mediumDetects Obfuscated Powershell via RUNDLL LAUNCHER
windows
Password Protected ZIP File Opened
mediumDetects the extraction of password protected ZIP archives. See the filename variable for more details on which file has been opened.
windows
Potential Application Whitelisting Bypass via Dnx.EXE
mediumDetects the execution of Dnx.EXE. The Dnx utility allows for the execution of C# code. Attackers might abuse this in order to bypass application whitelisting.
windows · process_creation
Potential CommandLine Obfuscation Using Unicode Characters
mediumDetects potential CommandLine obfuscation using unicode characters. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
windows · process_creation
Potential Obfuscated Ordinal Call Via Rundll32
mediumDetects execution of "rundll32" with potential obfuscated ordinal calls
windows · process_creation
Potential Secure Deletion with SDelete
mediumDetects files that have extensions commonly seen while SDelete is used to wipe files.
windows
Powershell Token Obfuscation - Powershell
mediumDetects TOKEN OBFUSCATION technique from Invoke-Obfuscation in Powershell scripts. Use this rule as a threat-hunting baseline to find obfuscated scripts in your environment. Once tested and tuned, consider deploying a production detection rule based on this hunting rule.
windows · ps_script
PUA - Potential PE Metadata Tamper Using Rcedit
mediumDetects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.
windows · process_creation
Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
mediumDetects the setting of a registry inside the "\Shell\Open\Command" value with PowerShell classes from the "System.Security.Cryptography" namespace. The PowerShell namespace "System.Security.Cryptography" provides classes for on-the-fly encryption and decryption. These can be used for example in decrypting malicious payload for defense evasion.
windows · registry_set
Suspicious Download Via Certutil.EXE
mediumDetects the execution of certutil with certain flags that allow the utility to download files.
windows · process_creation
Suspicious Usage of For Loop with Recursive Directory Search in CMD
mediumDetects suspicious usage of the cmd.exe 'for /f' loop combined with the 'tokens=' parameter and a recursive directory listing. This pattern may indicate an attempt to discover and execute system binaries dynamically, for example powershell, a technique sometimes used by attackers to evade detection. This behavior has been observed in various malicious lnk files.
windows · process_creation
Suspicious XOR Encoded PowerShell Command
mediumDetects presence of a potentially xor encoded powershell command
windows · process_creation
Decode Base64 Encoded Text
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
linux · process_creation
Decode Base64 Encoded Text -MacOs
lowDetects usage of base64 utility to decode arbitrary base64-encoded text
macos · process_creation
Dynamic CSharp Compile Artefact
lowWhen C# is compiled dynamically, a .cmdline file will be created as a part of the process. Certain processes are not typically observed compiling C# code, but can do so without touching disk. This can be used to unpack a payload for execution
windows · file_event
Potential Encoded PowerShell Patterns In CommandLine
lowDetects specific combinations of encoding methods in PowerShell via the commandline
windows · process_creation
Potential PowerShell Obfuscation Using Alias Cmdlets
lowDetects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts
windows · ps_script
Potential PowerShell Obfuscation Using Character Join
lowDetects specific techniques often seen used inside of PowerShell scripts to obfscuate Alias creation
windows · ps_script
Potential Suspicious Execution From GUID Like Folder Names
lowDetects potential suspicious execution of a GUID like folder name located in a suspicious location such as %TEMP% as seen being used in IcedID attacks. Use this rule to hunt for potentially suspicious activity stemming from uncommon folders.
windows · process_creation
Potentially Suspicious Long Filename Pattern - Linux
lowDetects the creation of files with unusually long filenames (100 or more characters), which may indicate obfuscation techniques used by malware such as VShell. This is a hunting rule to identify potential threats that use long filenames to evade detection. Keep in mind that on a legitimate system, such long filenames can and are common. Run this detection in the context of threat hunting rather than alerting. Adjust the threshold of filename length as needed based on your environment.
linux · file_event
Python Image Load By Non-Python Process
lowDetects the image load of "Python Core" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code. Various tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables. Threat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.
windows · image_load
Steganography Extract Files with Steghide
lowDetects extraction of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.
linux
Steganography Hide Files with Steghide
lowDetects embedding of files with usage of steghide binary, the adversaries may use this technique to prevent the detection of hidden information.
linux
Steganography Hide Zip Information in Picture File
lowDetects appending of zip file to image
linux
Steganography Unzip Hidden Information From Picture File
lowDetects extracting of zip file from image file
linux
Failed Code Integrity Checks
informationalDetects code integrity failures such as missing page hashes or corrupted drivers due unauthorized modification. This could be a sign of tampered binaries.
windows