{"id":"T1027.008","name":"Stripped Payloads","url":"https://attack.mitre.org/techniques/T1027/008","tactics":["stealth"],"platforms":["Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0019","stix_id":"x-mitre-detection-strategy--e4040d30-1f5a-4f80-9f06-f1c1d2a8c238","name":"Detection Strategy for Stripped Payloads Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0019","analytics":[{"id":"AN0055","stix_id":"x-mitre-analytic--e7b2c8da-d54d-446a-a7f6-062fe234a8cc","name":"Analytic 0055","description":"Executable or script payloads lacking symbol information and readable strings that are created or dropped by unusual or short-lived processes.","url":"https://attack.mitre.org/detectionstrategies/DET0019#AN0055","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:file","channel":"File Metadata Inspection (Low String Entropy, Missing PDB)","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"edr-file"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Payloads with extremely low string entropy may indicate stripped or obfuscated binaries"},{"field":"ParentProcessName","description":"Used to scope or whitelist common system builders, compilers, or admin tools"},{"field":"TimeWindow","description":"Correlates file creation and process spawning within a short timeframe"}],"live":true,"detection_strategies":["DET0019"],"techniques":["T1027.008"]},{"id":"AN0056","stix_id":"x-mitre-analytic--52d150da-36f4-43b4-96c4-b4fe33b012a2","name":"Analytic 0056","description":"Executable or binary files created without symbol tables or with stripped sections, especially by non-user shell processes or compilers invoked outside standard dev paths.","url":"https://attack.mitre.org/detectionstrategies/DET0019#AN0056","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"EXECVE","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"open, write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"hash, elf_info, file_metadata","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"StripFlags","description":"Flag combinations in compiled binaries indicating symbol table removal"},{"field":"DirectoryScope","description":"Whitelist compiler output directories to reduce false positives"},{"field":"FileSizeRange","description":"Heuristic boundaries for abnormal small or overly large stripped binaries"}],"live":true,"detection_strategies":["DET0019"],"techniques":["T1027.008"]},{"id":"AN0057","stix_id":"x-mitre-analytic--1b5b9ee8-69e6-41d4-a529-aa18afcdf453","name":"Analytic 0057","description":"Creation of run-only AppleScripts or Mach-O binaries lacking symbol table and string references, especially when dropped by user space scripting engines or staging apps.","url":"https://attack.mitre.org/detectionstrategies/DET0019#AN0057","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"file write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:osquery","channel":"code_signing, file_metadata","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"RunOnlyFlag","description":"AppleScript flag to disable reverse engineering (run-only compiled scripts)"},{"field":"ParentProcess","description":"Filter to isolate staging or suspicious scripting engines"},{"field":"SignedStatus","description":"Tuning based on unsigned vs. developer-signed payloads"}],"live":true,"detection_strategies":["DET0019"],"techniques":["T1027.008"]},{"id":"AN0058","stix_id":"x-mitre-analytic--a53e2979-2c41-44bc-b46e-13a19305e00d","name":"Analytic 0058","description":"Inbound binary payloads transferred over HTTP/S with compressed or encoded headers, lacking signature markers or metadata indicative of compiler/toolchain.","url":"https://attack.mitre.org/detectionstrategies/DET0019#AN0058","platforms":["Network Devices"],"log_source_references":[{"name":"NSM:Flow","channel":"http.log, files.log","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"MIMEType","description":"Tune for octet-stream or mismatched Content-Type headers"},{"field":"PayloadSize","description":"Payload threshold for executable-sized artifacts"},{"field":"TransferEncoding","description":"Suspicious base64 or chunked encoding not matching normal app behavior"}],"live":true,"detection_strategies":["DET0019"],"techniques":["T1027.008"]}],"live":true,"version":"1.0","techniques":["T1027.008"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}