Hide Artifacts T1564

Tactic: Stealth

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.

Events covered

29 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 4Sysmon service state changed
SysmonEvent ID 5Process terminated
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
SysmonEvent ID 16ServiceConfigurationChange
SysmonEvent ID 255Error report: UtcTime: UtcTime ID: ID Description: Description.
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 5136A directory service object was modified.
Defender-DeviceFileEventsanyFile activity
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFcreateFile or Directory Create
ESFrenameFile Rename
ESFwriteFile Write
Linux-AuditdEvent ID 1309EXECVE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
ServicingEvent ID 9Selectable update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier was successfully turned on.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 171 rules share fields, values, and exclusions.

Fields filtered most (100 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine62contains 44, regex_match 17, wildcard 4, eq 1, in 1, is_not_null 1--headless, (?i)\.cab|(-|\/)F:|\x5cAppData\x5c|(Local|Roaming)\x5cTemp\x5c, (?i)(\s+ADD\s+.*\/d.*0), (?i)(esentutl|\.exe)"?\s.*\/y\s.*\/d\s, (?i)-w(indowStyle)?\s+hidden
event.type54eq 50, in 3, ne 1start, creation, change, process_started, deletion
process_name54eq 25, in 15, starts_with 10, wildcard 3, regex_match 2., bash, cp, csh, dash
EventType46eq 33, in 13, ne 1exec, exec_event, connection_attempted, executed, modification
Image42ends_with 29, starts_with 7, contains 5, eq 2, is_not_null 2, wildcard 2, in 1, regex_match 1/dev/shm/, ./, /boot/, \attrib.exe, /media/
host.os.type32eq 31, in 1
process.args28eq 12, wildcard 8, in 7, starts_with 5, contains 3, ends_with 2, regex_match 1-o, -c, &, --options, /*/.*
TargetFilename19contains 6, starts_with 5, ends_with 3, regex_match 3, wildcard 3, eq 1(?<!\/)\b\w+(\.\w+)?:\w+(\.\w+)?$, .bat:zone, .cmd:zone, .dll:zone, .bat.exe
EventID18eq 184688, 1, 15, 4103, 4104
OriginalFileName18eq 18, in 1attrib.exe, sc.exe, findstr.exe, advancedrun.exe, cmd.exe
ParentImage15ends_with 6, is_not_null 6, eq 3, starts_with 3, contains 2\thor\thor64.exe, \webex\webexhost.exe, /boot/, /dev/shm/, /opt/.
event.category10eq 9, in 1process, file, authentication
parent_process_name10starts_with 3, eq 2, regex_match 2, in 1, ne 1, wildcard 1., ^C:\x5cUsers\x5cPublic, bash, launchd, osascript
Details9eq 8, is_not_null 1, length_compare 1dword (0x00000000), 0, 1, 0x00000000, 0x00000001
TargetObject8contains 4, ends_with 4, wildcard 2\(default), \control\safeboot\minimal\, \control\safeboot\minimal\hexnode agent\(default), \enablescripts, \microsoft\powershellcore\

Top indicator values (1365 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
441078
event.typeeq
creation
653
EventTypeeq
exec
28576
process_namestarts_with
.
938
EventTypein
exec
7201
EventTypein
exec_event
7149
EventTypein
start
7163
event.categoryeq
process
7142
CommandLinecontains
--headless
68
EventIDeq
4688
6317
EventIDeq
1
5241
Imagestarts_with
/dev/shm/
553
Imagestarts_with
/tmp/
558
Imagestarts_with
/var/tmp/
556
Imagestarts_with
./
426
Imagestarts_with
/boot/
428
process_namein
bash
5202
process_namein
csh
5159
process_namein
fish
5163
process_namein
ksh
5163
process_namein
sh
5197
process_namein
tcsh
5156
process_namein
zsh
5196
process_namein
dash
4170
Detailseq
dword (0x00000000)
438
OriginalFileNameeq
attrib.exe
45
ParentImageends_with
\thor\thor64.exe
4
ParentImageends_with
\webex\webexhost.exe
4
file.namestarts_with
.
47
process_nameeq
mount
49

Exclusions (660 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
ParentCommandLineeq
runc init
8
Imagestarts_with
/tmp/newroot/
4
ParentImageends_with
\thor\thor64.exe
4
ParentImageends_with
\webex\webexhost.exe
4
dest_ipcidr_match
10.0.0.0/8
4
dest_ipcidr_match
100.64.0.0/10
4
dest_ipcidr_match
127.0.0.0/8
4
dest_ipcidr_match
169.254.0.0/16
4
dest_ipcidr_match
172.16.0.0/12
4
dest_ipcidr_match
192.0.0.0/24
4
dest_ipcidr_match
192.0.2.0/24
4
dest_ipcidr_match
192.168.0.0/16
4
dest_ipcidr_match
192.175.48.0/24
4
dest_ipcidr_match
192.31.196.0/24
4
dest_ipcidr_match
192.52.193.0/24
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 65 rules

Elastic 67 rules

Splunk 30 rules

Kusto 6 rules

YARA-L 1 rule

Panther 2 rules