{"id":"T1553.005","name":"Mark-of-the-Web Bypass","url":"https://attack.mitre.org/techniques/T1553/005","tactics":["defense-impairment"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0257","stix_id":"x-mitre-detection-strategy--2556841e-474a-45c0-b827-4f5db6dcca31","name":"Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files","url":"https://attack.mitre.org/detectionstrategies/DET0257","analytics":[{"id":"AN0712","stix_id":"x-mitre-analytic--c7172412-6e48-45a0-a1c5-2eae892c1fc7","name":"Analytic 0712","description":"Detects extraction or mounting of container/archive files (e.g., .iso, .vhd, .zip) that originated from the Internet but whose contained files lack Zone.Identifier MOTW tagging. Correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside SmartScreen or Protected View.","url":"https://attack.mitre.org/detectionstrategies/DET0257#AN0712","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=15","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"WatchedExtensions","description":"Adjust monitored file types (e.g., .iso, .vhd, .zip, .gz, .rar) based on enterprise usage"},{"field":"TimeWindow","description":"Defines correlation window between extraction/mount and first execution of inner files"},{"field":"TrustedExtractionTools","description":"Whitelist known enterprise archivers and deployment mechanisms to reduce false positives"}],"live":true,"detection_strategies":["DET0257"],"techniques":["T1553.005"]}],"live":true,"version":"1.0","techniques":["T1553.005"]}],"sigma_rules":[{"id":"29e1c216-6408-489d-8a06-ee9d151ef819","title":"Suspicious Mount-DiskImage","author":"frack113","status":"test","level":"low","date":"2022-02-01","modified":null,"description":"Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.005/T1553.005.md#atomic-test-1---mount-iso-image","https://learn.microsoft.com/en-us/powershell/module/storage/mount-diskimage?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1553.005"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_mount_diskimage.yml","techniques":["T1553.005"],"cves":[]},{"id":"5947497f-1aa4-41dd-9693-c9848d58727d","title":"Suspicious Unblock-File","author":"frack113","status":"test","level":"medium","date":"2022-02-01","modified":null,"description":"Remove the Zone.Identifier alternate data stream which identifies the file as downloaded from the internet.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.005/T1553.005.md#atomic-test-3---remove-the-zoneidentifier-alternate-data-stream","https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.utility/unblock-file?view=powershell-7.2"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1553.005"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_unblock_file.yml","techniques":["T1553.005"],"cves":[]},{"id":"902cedee-0398-4e3a-8183-6f3a89773a96","title":"Suspicious Invoke-Item From Mount-DiskImage","author":"frack113","status":"test","level":"medium","date":"2022-02-01","modified":null,"description":"Adversaries may abuse container files such as disk image (.iso, .vhd) file formats to deliver malicious payloads that may not be tagged with MOTW.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1553.005/T1553.005.md#atomic-test-2---mount-an-iso-image-and-run-executable-from-the-iso","https://learn.microsoft.com/en-us/powershell/module/storage/mount-diskimage?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.defense-impairment","attack.t1553.005"],"path":"rules/windows/powershell/powershell_script/posh_ps_run_from_mount_diskimage.yml","techniques":["T1553.005"],"cves":[]},{"id":"9a025188-6f2d-42f8-bb2f-d3a83d24a5af","title":"Windows AppX Deployment Unsigned Package Installation","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-03","modified":null,"description":"Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXDeployment-Server events","references":["https://docs.microsoft.com/en-us/powershell/module/appx/add-appxpackage","https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","service":"appxdeployment-server"},"tags":["attack.execution","attack.defense-impairment","attack.t1204.002","attack.t1553.005"],"path":"rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_unsigned_package_installation.yml","techniques":["T1204.002","T1553.005"],"cves":[]},{"id":"af5732ed-764e-489d-826d-0447c8b36242","title":"Windows MSIX Package Support Framework AI_STUBS Execution","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"low","date":"2025-11-03","modified":null,"description":"Detects execution of Advanced Installer MSIX Package Support Framework (PSF) components, specifically AI_STUBS executables with original filename 'popupwrapper.exe'.\nThis activity may indicate malicious MSIX packages build with Advanced Installer leveraging the Package Support Framework to bypass application control restrictions.\n","references":["https://redcanary.com/blog/threat-intelligence/msix-installers/","https://redcanary.com/threat-detection-report/techniques/installer-packages/","https://learn.microsoft.com/en-us/windows/msix/package/package-support-framework","https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.defense-impairment","attack.t1218","attack.t1553.005","attack.t1204.002"],"path":"rules/windows/process_creation/proc_creation_win_msix_ai_stub_execution.yml","techniques":["T1218","T1553.005","T1204.002"],"cves":[]},{"id":"e54279c7-4910-4e2c-902c-c56a25b549f6","title":"Windows AppX Deployment Full Trust Package Installation","author":"Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2025-11-03","modified":null,"description":"Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated privileges outside normal AppX container restrictions","references":["https://www.splunk.com/en_us/blog/security/msix-weaponization-threat-detection-splunk.html"],"logsource":{"product":"windows","service":"appxdeployment-server"},"tags":["attack.execution","attack.defense-impairment","attack.t1204.002","attack.t1553.005"],"path":"rules/windows/builtin/appxdeployment_server/win_appxpackaging_server_full_trust_package_installation.yml","techniques":["T1204.002","T1553.005"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-0411","state":"mapped","mapping_types":["exploitation_technique"]},{"cveID":"CVE-2023-36884","state":"stale","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}