Obfuscated Files or Information T1027
Tactic: Stealth
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Events covered
30 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 284 rules share fields, values, and exclusions.
Fields filtered most (116 distinct)
These fields appear most often in rule filters.
Top indicator values (2224 distinct)
These values appear most often in rule predicates.
Exclusions (818 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 129 rules
- Base64 Encoded PowerShell Command Detected
- Binary Padding - Linux
- Binary Padding - MacOS
- Certificate Exported Via Certutil.EXE
- ConvertTo-SecureString Cmdlet Usage Via CommandLine
- Csc.EXE Execution Form Potentially Suspicious Parent
- Decode Base64 Encoded Text
- Decode Base64 Encoded Text -MacOs
- Dynamic .NET Compilation Via Csc.EXE
- Dynamic .NET Compilation Via Csc.EXE - Hunting
- Dynamic CSharp Compile Artefact
- Encoded PowerShell payload deployed (PowerShell)
- Encoded PowerShell payload deployed via process execution
- Encoded PowerShell payload deployed via service
- Failed Code Integrity Checks
- File Decoded From Base64/Hex Via Certutil.EXE
- File Encoded To Base64 Via Certutil.EXE
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE
- Findstr Launching .lnk File
- HackTool - CrackMapExec PowerShell Obfuscation
- Invocation Of Crypto-Classes From The "Cryptography" PowerShell Namespace
- Invoke-Obfuscation CLIP+ Launcher
- Invoke-Obfuscation CLIP+ Launcher - PowerShell
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module
- Invoke-Obfuscation CLIP+ Launcher - Security
- Invoke-Obfuscation CLIP+ Launcher - System
- Invoke-Obfuscation COMPRESS OBFUSCATION
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell Module
- Invoke-Obfuscation COMPRESS OBFUSCATION - Security
- Invoke-Obfuscation COMPRESS OBFUSCATION - System
- Invoke-Obfuscation Obfuscated IEX Invocation
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module
- Invoke-Obfuscation Obfuscated IEX Invocation - Security
- Invoke-Obfuscation Obfuscated IEX Invocation - System
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell Module
- Invoke-Obfuscation RUNDLL LAUNCHER - Security
- Invoke-Obfuscation RUNDLL LAUNCHER - System
- Invoke-Obfuscation STDIN+ Launcher
- Invoke-Obfuscation STDIN+ Launcher - Powershell
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module
- Invoke-Obfuscation STDIN+ Launcher - Security
- Invoke-Obfuscation STDIN+ Launcher - System
- Invoke-Obfuscation VAR+ Launcher
- Invoke-Obfuscation VAR+ Launcher - PowerShell
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module
- Invoke-Obfuscation VAR+ Launcher - Security
- Invoke-Obfuscation VAR+ Launcher - System
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System
- Invoke-Obfuscation Via Stdin
- Invoke-Obfuscation Via Stdin - Powershell
- Invoke-Obfuscation Via Stdin - PowerShell Module
- Invoke-Obfuscation Via Stdin - Security
- Invoke-Obfuscation Via Stdin - System
- Invoke-Obfuscation Via Use Clip
- Invoke-Obfuscation Via Use Clip - Powershell
- Invoke-Obfuscation Via Use Clip - PowerShell Module
- Invoke-Obfuscation Via Use Clip - Security
- Invoke-Obfuscation Via Use Clip - System
- Invoke-Obfuscation Via Use MSHTA
- Invoke-Obfuscation Via Use MSHTA - PowerShell
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module
- Invoke-Obfuscation Via Use MSHTA - Security
- Invoke-Obfuscation Via Use MSHTA - System
- Invoke-Obfuscation Via Use Rundll32 - PowerShell
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module
- Invoke-Obfuscation Via Use Rundll32 - Security
- Invoke-Obfuscation Via Use Rundll32 - System
- Obfuscated payload transfered via service name - Tchopper (command)
- Obfuscated PowerShell MSI Install via WindowsInstaller COM
- Operation Wocao Activity
- Operation Wocao Activity - Security
- Password Protected ZIP File Opened
- Password Protected ZIP File Opened (Email Attachment)
- Password Protected ZIP File Opened (Suspicious Filenames)
- Ping Hex IP
- Potential Application Whitelisting Bypass via Dnx.EXE
- Potential CommandLine Obfuscation Using Unicode Characters
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image
- Potential Emotet Activity
- Potential Encoded PowerShell Patterns In CommandLine
- Potential Obfuscated Ordinal Call Via Rundll32
- Potential PowerShell Command Line Obfuscation
- Potential PowerShell Obfuscation Using Alias Cmdlets
- Potential PowerShell Obfuscation Using Character Join
- Potential PowerShell Obfuscation Via Reversed Commands
- Potential PowerShell Obfuscation Via WCHAR/CHAR
- Potential Secure Deletion with SDelete
- Potential Suspicious Execution From GUID Like Folder Names
- Potential Winnti Dropper Activity
- Potentially Suspicious Long Filename Pattern - Linux
- PowerShell Base64 Encoded Invoke Keyword
- PowerShell Base64 Encoded Reflective Assembly Load
- PowerShell Base64 Encoded WMI Classes
- Powershell Token Obfuscation - Powershell
- Powershell Token Obfuscation - Process Creation
- Process Execution From Shared Memory Directory
- PUA - DefenderCheck Execution
- PUA - Potential PE Metadata Tamper Using Rcedit
- Python Image Load By Non-Python Process
- Python One-Liners with Base64 Decoding
- Python One-Liners with Base64 Decoding - Linux
- Registry Set With Crypto-Classes From The "Cryptography" PowerShell Namespace
- Renamed AutoIt Execution
- Steganography Extract Files with Steghide
- Steganography Hide Files with Steghide
- Steganography Hide Zip Information in Picture File
- Steganography Unzip Hidden Information From Picture File
- Suspicious Download Via Certutil.EXE
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix
- Suspicious File Downloaded From Direct IP Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE
- Suspicious File Encoded To Base64 Via Certutil.EXE
- Suspicious Filename with Embedded Base64 Commands
- Suspicious Get-Variable.exe Creation
- Suspicious Space Characters in RunMRU Registry Path - ClickFix
- Suspicious Space Characters in TypedPaths Registry Path - FileFix
- Suspicious SYSTEM User Process Creation
- Suspicious Usage of For Loop with Recursive Directory Search in CMD
- Suspicious XOR Encoded PowerShell Command
- Turla Group Commands May 2020
- Visual Basic Command Line Compiler Usage
Elastic 88 rules
- AppleScript Decoded via Base64
- Base16 or Base32 Encoding/Decoding Activity
- Base64 Decoded Payload Piped to Interpreter
- Base64 Encoded String Execution via Osascript
- Base64 or Xxd Decode Argument Evasion
- Base64 Shebang Payload Decoded via Built-in Utility
- Binary Content Copy via Cmd.exe
- Command Line Obfuscation via Whitespace Padding
- Command Obfuscation via Unicode Modifier Letters
- Command Obfuscation via Unicode Modifier Letters
- Data Encrypted and Archived
- Data Encrypted and Archived
- Data Encrypted via OpenSSL Utility
- Decoded or Decrypted Payload Written to Suspicious Directory
- Decoded Payload Piped to Interpreter
- Decoded Payload Piped to Interpreter Detected via Defend for Containers
- Deprecated - Encoded Executable Stored in the Registry
- Deprecated - Potential PowerShell Obfuscated Script
- Dynamic IEX Reconstruction via Method String Access
- Embedded Payload Dropped and Executed
- Encoded Payload Detected via Defend for Containers
- Executable File Creation via Base64
- Execution of a DNGUard Protected Program
- Execution of a File Dropped by OpenSSL
- Execution via Obfuscated Windows Script
- File Compressed or Archived into Common Format by Unsigned Process
- GenAI Process Compiling or Generating Executables
- GenAI Process Performing Encoding/Chunking Prior to Network Activity
- High Command Line Entropy Detected for Privileged Commands
- Initial Access or Execution via Microsoft Office Application
- Linux Compilation in Suspicious Directory
- Linux Payload Decoded and Decrypted via Built-in Utility
- Long Base64 Command Execution via Interactive Shell
- Long Base64 Encoded Command via Scripting Interpreter
- Long Base64 Encoded Interpreter Command Line
- Microsoft Build Engine Started an Unusual Process
- Multi-Base64 Decoding Attempt from Suspicious Location
- Multi-Layered Deobfuscation via Unusual Parent
- Network File Unzipped via Unsigned or Untrusted Binary
- Oversized DLL Creation followed by SideLoad
- Payload Decoded and Decrypted via Built-In Utilities
- Payload Decoded via CertUtil
- Potential Antimalware Scan Interface Bypass via PowerShell
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential Evasion via Oversized Image Load
- Potential Executable Stored in the Registry
- Potential Hex Payload Execution via Command-Line
- Potential Hex Payload Execution via Common Utility
- Potential Obfuscated Script Execution
- Potential PowerShell Obfuscated Script via High Entropy
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via Character Array Reconstruction
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
- Potential PowerShell Obfuscation via High Numeric Character Proportion
- Potential PowerShell Obfuscation via High Special Character Proportion
- Potential PowerShell Obfuscation via Invalid Escape Sequences
- Potential PowerShell Obfuscation via Reverse Keywords
- Potential PowerShell Obfuscation via Special Character Overuse
- Potential PowerShell Obfuscation via String Concatenation
- Potential PowerShell Obfuscation via String Reordering
- PowerShell Obfuscation via Negative Index String Reversal
- PowerShell Script with Encryption/Decryption Capabilities
- PowerShell Suspicious Payload Encoded and Compressed
- ROT Encoded Python Script Execution
- ROT encoded Python Script Execution
- Rundll32 or Regsvr32 Executing an OverSized File
- Suspicious .NET Code Compilation
- Suspicious Base64 String Command-line
- Suspicious Content Extracted or Decompressed via Funzip
- Suspicious DD Execution
- Suspicious Deobfuscation via Shell Script
- Suspicious Echo Execution
- Suspicious Execution from an Oversized Executable
- Suspicious Execution with NodeJS
- Suspicious File Delivery via HTML Smuggling
- Suspicious File Overwrite and Modification via Echo
- Suspicious HTML File Creation
- Suspicious Interpreter Execution from Stdin
- Suspicious JavaScript Execution via Deno
- Suspicious OpenSSL Execution via macOS Application
- Suspicious Oversized Script Execution
- Suspicious Portable Executable Encoded in Powershell Script
- Suspicious Powershell Script
- Suspicious Python Encoded Payload Execution
- Suspicious Python One-Liner with Encoded Payload Execution
- Suspicious Windows Command Shell Arguments
- Suspicious Windows Powershell Arguments
- Unusual Base64 Encoding/Decoding Activity
Splunk 52 rules
- Certutil Execution (Sysmon)
- Certutil Execution (Windows Event Log)
- Certutil File Download (PowerShell)
- Certutil File Download (Sysmon)
- Certutil File Download (Windows Event Log)
- Certutil Obfuscate_Encode Files (PowerShell)
- Certutil Obfuscate_Encode Files (Sysmon)
- Certutil Obfuscate_Encode Files (Windows Event Log)
- Cisco Secure Firewall - Lumma Stealer Activity
- Cisco Secure Firewall - Repeated Malware Downloads
- Cisco Secure Firewall - Snort Rule Triggered Across Multiple Hosts
- Command Line Homoglyphs - Windows (PowerShell)
- Command Line Homoglyphs - Windows (Sysmon)
- Command Line Homoglyphs - Windows (Windows Event Log)
- Compressed File Execution (Windows Event Log)
- CSC Execution (Windows Event Log)
- CSC Net On The Fly Compilation
- Curl Execution with Percent Encoded URL
- DLL Concatenation (PowerShell)
- DLL Concatenation (Sysmon)
- DLL Concatenation (Windows Event Log)
- Encoded Powershell Command (PowerShell)
- Encoded Powershell Command (Sysmon)
- Encoded Powershell Command (Windows Event Log)
- Impacket atexec.py Execution (PowerShell)
- Impacket atexec.py Execution (Sysmon)
- Impacket atexec.py Execution (Windows Event Log)
- Impacket atexec.py Scheduled Task Creation (Windows Event Log)
- Impacket atexec.py Temp File Creation (Sysmon)
- Impacket atexec.py Temp File Creation (Windows Event Log)
- Linux Decode Base64 to Shell
- Linux Obfuscated Files or Information Base64 Decode
- Linux Suspicious GCC Invocation Building Init Shared Object
- Malicious PowerShell Process - Encoded Command
- Obfuscated Powershell Techniques (PowerShell)
- PowerShell CreateDecryptor (PowerShell)
- PowerShell CreateDecryptor (Sysmon)
- PowerShell CreateDecryptor (Windows Event Log)
- Powershell Creating Thread Mutex
- Powershell Enable SMB1Protocol Feature
- Powershell Fileless Script Contains Base64 Encoded Content
- PowerShell WebRequest Using Memory Stream
- Suspicious csc.exe Source File Folder (Sysmon)
- Suspicious csc.exe Source File Folder (Windows Event Log)
- Wermgr Process Create Executable File
- Windows Command Obfuscation with Environment Variable Substrings
- Windows Njrat Fileless Storage via Registry
- Windows Obfuscated Files or Information via RAR SFX
- Windows PowerShell Process Implementing Manual Base64 Decoder
- Windows Registry Payload Injection
- Windows Snake Malware File Modification Crmlog
- Windows TinyCC Shellcode Execution
Kusto 12 rules
- Base64 encoded Windows process command-lines
- Base64 encoded Windows process command-lines (Normalized Process Events)
- Cisco Cloud Security - Windows PowerShell User-Agent Detected
- Ingress Tool Transfer - Certutil
- NRT Base64 Encoded Windows Process Command-lines
- NRT Process executed from binary hidden in Base64 encoded file
- Powershell Empire Cmdlets Executed in Command Line
- PowerShell Encoded Command Execution (Living off the Land)
- Process Creation with Suspicious CommandLine Arguments
- Process executed from binary hidden in Base64 encoded file
- TEARDROP memory-only dropper
- Votiro - File Blocked in Email
YARA-L 2 rules
- Suspicious Download Via Certutil.EXE
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE