{"id":"T1027.018","name":"Invisible Unicode","url":"https://attack.mitre.org/techniques/T1027/018","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0920","stix_id":"x-mitre-detection-strategy--ded7322c-64ba-4f6b-9aca-77a537798cab","name":"Detection Strategy for Invisible Unicode","url":"https://attack.mitre.org/detectionstrategies/DET0920","analytics":[{"id":"AN2063","stix_id":"x-mitre-analytic--1a9f097a-d5b9-424d-ae20-19ed73eb9dcf","name":"Analytic 2063","description":"Detection identifies execution of scripts or files that appear visually benign (low printable character ratio) but result in runtime decoding, dynamic evaluation, and subsequent process or network activity. Correlation links script execution with abnormal Unicode density and follow-on behavior such as child process creation or outbound connections.","url":"https://attack.mitre.org/detectionstrategies/DET0920#AN2063","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:PowerShell","channel":"EventCode=4103, 4104, 4105, 4106","data_component":"DC0029","data_component_name":"Script Execution","log_source_slug":"wineventlog-powershell"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=7","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"AllocationSizeThreshold","description":"To tune for atypical virtual memory allocations that might indicate non-rendering characters in dense files"},{"field":"ExecutionContext","description":"Allows tuning for atypical processes from script execution (e.g., powershell.exe, wscript.exe, mshta.exe)"},{"field":"UnicodeDensityThreshold","description":"Tune for invisible characters, or atypical amounts of Unicode characters (U+...)"}],"live":true,"detection_strategies":["DET0920"],"techniques":["T1027.018"]},{"id":"AN2064","stix_id":"x-mitre-analytic--a32c4f38-feaf-4291-9dad-3043114b4d37","name":"Analytic 2064","description":"Detection identifies execution of scripts containing high concentrations of invisible Unicode characters followed by decoding or interpretation behaviors (e.g., base64 decode, eval) and subsequent process or network activity. Emphasis is placed on mismatch between file entropy/structure and execution output.","url":"https://attack.mitre.org/detectionstrategies/DET0920#AN2064","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"stat and lstat syscall results on files, including inode and permission info","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"execve of script/interpreter (bash, python, node) with suspicious encoded or non-printable content","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"DecodeUtility","description":"May include base64"},{"field":"EntropyThreshold","description":"Useful for tuning sections containing high entropy indicative of Unicode sequences"}],"live":true,"detection_strategies":["DET0920"],"techniques":["T1027.018"]},{"id":"AN2065","stix_id":"x-mitre-analytic--6195e912-ed73-4ec7-a03b-097631ec0b26","name":"Analytic 2065","description":"Detection identifies execution of scripts or applications containing invisible Unicode payloads reconstructed at runtime, correlated with abnormal AppleScript, JavaScript for Automation, or shell execution and subsequent process or network behavior inconsistent with visible file content. ","url":"https://attack.mitre.org/detectionstrategies/DET0920#AN2065","platforms":["macOS"],"log_source_references":[{"name":"NSM:Flow","channel":"log entries indicating network connection initiation on macOS","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"nsm-flow"},{"name":"macos:unifiedlog","channel":"Execution of osascript, sh, bash, zsh, installer, open","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macOS:unifiedlog","channel":"looking for file access to scripts with abnormal encoding patterns","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ExecutionContext","description":"Use of abnormal AppleScript or JavaScript functions (such as eval()) not typically expected"},{"field":"UnicodeCharacterSet","description":"Specific unicode ranges monitored (zero-width, PUA, bidi) "}],"live":true,"detection_strategies":["DET0920"],"techniques":["T1027.018"]}],"live":true,"version":"1.0","techniques":["T1027.018"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}