Obfuscated Files or Information T1027

Tactic: Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.

Events covered

30 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
Security-AuditingEvent ID 4656A handle to an object was requested.
Security-AuditingEvent ID 4658The handle to an object was closed.
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4698A scheduled task was created.
Security-AuditingEvent ID 4799A security-enabled local group membership was enumerated.
Security-AuditingEvent ID 5038Code integrity determined that the image hash of a file is not valid.
Security-AuditingEvent ID 5379Credential Manager credentials were read.
Security-AuditingEvent ID 6281Code Integrity determined that the page hashes of an image file are not valid.
Defender-DeviceEventsExploitGuardNonMicrosoftSignedBlockedExploit Guard non-Microsoft signed image (blocked)
Defender-DeviceFileEventsanyFile activity
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFwriteFile Write
Linux-AuditdEvent ID 1309EXECVE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 800Event ID 800
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 284 rules share fields, values, and exclusions.

Fields filtered most (116 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine119contains 78, regex_match 34, wildcard 15, match 9, is_not_null 4, in 3, length_compare 3, ends_with 1, eq 1, is_null 1(?i)(copy|more|Get-Content|type|cat|gc)\s+.*?((\/b\s+\S+\..., (?i)CreateDecryptor, -d, -encode, base64
process_name69eq 39, in 27, starts_with 19, wildcard 8, regex_match 6base64, bash, base16, base32, csh
EventType56eq 42, in 10, ne 8exec, start, deletion, ProcessRollup2, exec_event
Image52ends_with 37, contains 5, starts_with 5, eq 4, is_not_null 3, is_null 2, regex_match 2, wildcard 1\powershell.exe, \pwsh.exe, \certutil.exe, \cmd.exe, \csc.exe
event.type47eq 46, in 1start, change, creation
EventID42eq 424688, 4104, 1, 4103, 11
process.args37eq 28, wildcard 15, in 10, starts_with 8, contains 6, ends_with 1, regex_match 1-c, -base64, *-*d*, -a, -d
OriginalFileName34eq 31, in 2, contains 1, wildcard 1powershell.exe, pwsh.dll, certutil.exe, powershell_ise.exe, bitsadmin.exe
ScriptBlockText29contains 17, regex_match 8, eq 6, in 5, ends_with 1, match 1frombase64string, &&, -value (-join(, "(\{\d\}){2,}"\s*-f, $env:comspec[4
host.os.type19eq 18, in 1
TargetFilename14starts_with 5, ends_with 4, contains 3, wildcard 2, regex_match 1?:\programdata\, ?:\users\, ?:\windows\tasks\, .cmdline, .exe
parent_process_name14eq 8, in 3, starts_with 3, wildcard 3, contains 1, regex_match 1explorer.exe, Claude, Copilot, Cursor, mshta.exe
ParentImage13ends_with 4, is_not_null 4, starts_with 4, eq 3, contains 1, wildcard 1., /bin/lua, /bin/perl, /bin/php, /boot/
process.args_count13eq 4, le 4, ge 3, gt 22, 1, 3, 4
ImagePath12contains 11, match 2, regex_match 1&&, /c, -f, "set, $

Top indicator values (2224 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
461078
EventTypeeq
exec
27576
EventIDeq
4688
16317
EventIDeq
4104
11269
EventIDeq
1
9241
Imageends_with
\powershell.exe
14179
Imageends_with
\pwsh.exe
13165
process.argseq
-c
14107
process.argseq
enc
1216
process.argseq
-e
946
OriginalFileNameeq
powershell.exe
13138
OriginalFileNameeq
pwsh.dll
13112
OriginalFileNameeq
certutil.exe
930
process_nameeq
openssl
1328
process_namestarts_with
python
1371
process_namein
base64
1220
process_namein
bash
12202
process_namein
sh
12197
process_namein
zsh
12196
process_namein
csh
11159
process_namein
dash
11170
process_namein
fish
11163
process_namein
ksh
11163
process_namein
tcsh
11156
process_namein
base16
912
Provider_Nameeq
service control manager
1050
CommandLinecontains
b64decode
99
CommandLinecontains
base64
919
EventTypein
exec
9201
event.categoryeq
process
9142

Exclusions (818 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
user.ideq
s-1-5-18
8
CurrentDirectorywildcard
/opt/zeek
4
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/usr/local/zeek
4
CurrentDirectorywildcard
/proc/self/fd/*/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek_old_install
3
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/opt/zeek
3
parent_process_namestarts_with
python
4
ParentCommandLinecontains
extendedglob
3
ParentImagewildcard
/tmp/.mount_*/usr/share/cursor/cursor
3
parent_process_nameeq
zsh
3
process.Ext.effective_parent.executableeq
/Library/Application...
3
process.code_signature.trustedeq
true
3
process_nameeq
cmd.exe
3
CommandLineeq
/usr/bin/perl /usr/bin/shasum -a 256
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 129 rules

Elastic 88 rules

Splunk 52 rules

Kusto 12 rules

YARA-L 2 rules

Panther 1 rule