{"id":"T1027.013","name":"Encrypted/Encoded File","url":"https://attack.mitre.org/techniques/T1027/013","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0087","stix_id":"x-mitre-detection-strategy--d70b8fdd-de14-4143-a350-56e3b885b37b","name":"Encrypted or Encoded File Payload Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0087","analytics":[{"id":"AN0237","stix_id":"x-mitre-analytic--4f985435-9144-4a8f-aca0-598f788855b7","name":"Analytic 0237","description":"Detection of processes that load or decode encrypted/encoded files in memory and subsequently execute or inject them, indicating payload unpacking or memory-resident malware.","url":"https://attack.mitre.org/detectionstrategies/DET0087#AN0237","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"Image","description":"Path of decoder utilities (e.g., certutil.exe, powershell.exe) can vary across environments."},{"field":"CommandLine","description":"Base64/hex strings used may change per encoded payload."},{"field":"TimeWindow","description":"The duration between file decode and execution may differ across implementations."}],"live":true,"detection_strategies":["DET0087"],"techniques":["T1027.013"]},{"id":"AN0238","stix_id":"x-mitre-analytic--e9de9003-46e9-438f-929a-94a33c2eb5bd","name":"Analytic 0238","description":"Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk.","url":"https://attack.mitre.org/detectionstrategies/DET0087#AN0238","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"UserContext","description":"Normal usage of `base64`, `openssl`, or `gpg` varies by user/role."},{"field":"ProcessLineage","description":"Parent-child process chains may differ across deployments."},{"field":"TimeWindow","description":"Time between decode and execution is implementation-specific."}],"live":true,"detection_strategies":["DET0087"],"techniques":["T1027.013"]},{"id":"AN0239","stix_id":"x-mitre-analytic--0e832ea1-a261-4bdd-8fc8-ae049468c347","name":"Analytic 0239","description":"Detection of encoded payloads being decoded and executed in-memory using scripting tools or third-party decoders.","url":"https://attack.mitre.org/detectionstrategies/DET0087#AN0239","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log stream","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"es_event_exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"memory mapping","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ScriptContent","description":"Encoded payload content varies across adversaries."},{"field":"ExecutionChain","description":"Sequence of tools or scripts executed can differ."},{"field":"UserContext","description":"May depend on whether user is admin, daemon, or system account."}],"live":true,"detection_strategies":["DET0087"],"techniques":["T1027.013"]}],"live":true,"version":"1.0","techniques":["T1027.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}