Sigma Rule Library

MITRE ATT&CK technique

Obfuscated Files or Information detection rulesT1027

Obfuscated Files or Information (T1027) is a MITRE ATT&CK technique in the Stealth tactic. This page lists the 125 community-maintained Sigma detection rules in the library mapped to T1027 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, linux, macos.

Top products

Tactic