{"id":"T1027.014","name":"Polymorphic Code","url":"https://attack.mitre.org/techniques/T1027/014","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0324","stix_id":"x-mitre-detection-strategy--380da3b2-d92f-4361-b187-cedc8a118e0f","name":"Detection Strategy for Polymorphic Code Mutation and Execution","url":"https://attack.mitre.org/detectionstrategies/DET0324","analytics":[{"id":"AN0919","stix_id":"x-mitre-analytic--786c54fa-8a9f-41bc-aa22-c4a4f6a93bd7","name":"Analytic 0919","description":"Identifies self-modifying executables that exhibit changes in binary hash, entropy, or memory sections during or between executions—often tied to dynamic unpacking or decryption behaviors.","url":"https://attack.mitre.org/detectionstrategies/DET0324#AN0919","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Tune based on expected baseline entropy for executables; higher values may indicate polymorphic packing."},{"field":"TimeWindow","description":"Correlate rapid process spawn + image load activity suggesting mutation engine usage."},{"field":"ParentProcessPatterns","description":"Define expected or suspicious parent-child chains (e.g., script runner -> encoded PE)"}],"live":true,"detection_strategies":["DET0324"],"techniques":["T1027.014"]},{"id":"AN0920","stix_id":"x-mitre-analytic--6ed3efbf-c060-4c7f-8d8b-0e93f65a0790","name":"Analytic 0920","description":"Detects files or processes where execution results in frequent re-creation or modification of ELF binaries or interpreter scripts, often using chmod + execve with abnormal entropy.","url":"https://attack.mitre.org/detectionstrategies/DET0324#AN0920","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"mmap","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"chmod","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"WriteExecThreshold","description":"Tune to alert on write followed by chmod + exec in quick succession."},{"field":"FileEntropyDeviation","description":"Detect high deviation from average entropy score of baseline ELF/script files."},{"field":"ExecutionFrequency","description":"Abnormal burst executions of file with identical functionality but varying hash."}],"live":true,"detection_strategies":["DET0324"],"techniques":["T1027.014"]},{"id":"AN0921","stix_id":"x-mitre-analytic--8fba0b53-2aca-4cca-8856-714e0f05665b","name":"Analytic 0921","description":"Tracks modification of executables or interpreter payloads (e.g., Mach-O, dylib) that mutate across runs—using scripting engines, JIT compilers, or side-loaded plugins.","url":"https://attack.mitre.org/detectionstrategies/DET0324#AN0921","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"code signature/memory protection","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"file open/write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"fs-fsusage"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_MMAP","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"ScriptEnginePatterns","description":"Detection may vary based on whether Python/Swift/AppleScript is used to mutate payloads."},{"field":"MachOEntropyThreshold","description":"Entropy tuning based on expected baseline for system vs user binaries."},{"field":"SignedBinaryChangeRate","description":"Helps flag apps that change but maintain signed status across invocations."}],"live":true,"detection_strategies":["DET0324"],"techniques":["T1027.014"]}],"live":true,"version":"1.0","techniques":["T1027.014"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}