Deobfuscate/Decode Files or Information T1140

Tactic: Stealth

Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on how they intend to use it. Methods for doing that include built-in functionality of malware or by using utilities present on the system.

Events covered

15 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 102 rules share fields, values, and exclusions.

Fields filtered most (63 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine44contains 33, wildcard 12, regex_match 6, ends_with 4, is_not_null 4, length_compare 3, match 3, is_null 1, starts_with 1decode, tvqqaamaaaaeaaa, --decode, -d, -e
process_name39eq 23, in 18, starts_with 17, wildcard 5, regex_match 2base64, bash, base16, base32, csh
EventType35eq 27, in 6, ne 3exec, ProcessRollup2, exec_event, deletion, modification
event.type35eq 35start
process.args28eq 20, in 12, wildcard 12, starts_with 9, contains 8, ends_with 1, regex_match 1-base64, -c, -d, *-*d*, -a
host.os.type16eq 15, in 1
Image14ends_with 11, starts_with 2, regex_match 1\certutil.exe, /openssl, /wget, (system32|syswow64)\\windowspowershell\\v1\.0\\powershell..., /bash
Esql.script_block_pattern_count10ge 101, 2, 20, 5
Esql.script_block_length9gt 9500, 1000
EventID9eq 94688, 1
ScriptBlockText9contains 5, in 4, eq 3, match 1$env:comspec[4, $pshome[, $shellid[, +, .createdecryptor
ParentImage7is_not_null 5, starts_with 1, wildcard 1., /boot/, /dev/shm/, /dev/shm/*, /etc/profile.d/*
event.category7eq 7process
parent_process_name7eq 4, in 3, ends_with 1, starts_with 1, wildcard 1explorer.exe, *.bin, *.lua, *.pl, \WmiPrvSE.exe
OriginalFileName5eq 5certutil.exe, mshta.exe, powershell.exe, pwsh.dll

Top indicator values (1144 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
351078
EventTypeeq
exec
25576
process.argseq
-c
12107
process.argseq
-e
1046
process.argseq
enc
916
process.argseq
base64
77
process_namestarts_with
python
1271
process_namestarts_with
perl
936
process_namestarts_with
ruby
936
process_nameeq
openssl
1128
process_namein
base64
1120
process_namein
bash
11202
process_namein
csh
11159
process_namein
dash
11170
process_namein
fish
11163
process_namein
ksh
11163
process_namein
sh
11197
process_namein
tcsh
11156
process_namein
zsh
11196
process_namein
base16
912
process_namein
base32
914
process_namein
base64mime
710
process_namein
base64pem
710
process.argsin
-d
914
process.argsin
-base64
811
process.argsin
-t
79
process.argsin
-u
79
EventIDeq
4688
7317
event.categoryeq
process
7142
process.argscontains
base64
77

Exclusions (428 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_namestarts_with
python
4
CurrentDirectorywildcard
/opt/zeek
3
CurrentDirectorywildcard
/proc/self/fd/*/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek
3
CurrentDirectorywildcard
/usr/local/zeek_old_install
3
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/opt/zeek
3
CurrentDirectorywildcard
/var/lib/docker/overlay2/*/usr/local/zeek
3
ParentCommandLinecontains
extendedglob
3
ParentImagewildcard
/tmp/.mount_*/usr/share/cursor/cursor
3
parent_process_nameeq
zsh
3
process.Ext.effective_parent.executableeq
/Library/Application...
3
user.ideq
s-1-5-18
3
CommandLineeq
/usr/bin/perl /usr/bin/shasum -a 256
2
CurrentDirectoryeq
/home/deploy
2
ParentCommandLinein
/bin/sh /var/lib/dpkg/info/nmap-common.postinst configure
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 20 rules

Elastic 62 rules

Splunk 6 rules

Kusto 13 rules

YARA-L 1 rule