Techniques › T1564
T1564 Hide Artifacts
stealth — ESXi, Linux, macOS, Office Suite, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
5
analytics
10
Sigma rules tagged attack.t1564
0
KEV CVEs mapped here
<p>Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.</p><p>Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0502 Detection Strategy for Hidden Artifacts Across Platforms v1.0
AN1384 WindowsAbuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.Tunable:
FileExtensionsADSDetectionAN1385 LinuxHidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories.auditd:FILECreation of hidden files (.*) in sensitive directories (/etc, /var, /usr/bin)→ DC0039 File CreationTunable:DirectoryScopeAttributeFlagsAN1386 macOSHidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths.macos:unifiedlogCreation of LaunchAgents/LaunchDaemons in hidden or non-standard directories→ DC0039 File CreationTunable:HiddenDirectoriesAN1387 ESXiAbuse of VMFS or ESXi shell to hide datastore files, renaming/moving VMDK or VMX files into hidden directories. Defender view: anomalous ESXi shell commands or file operations obscuring VM artifacts.esxi:shellmv, rename, or chmod commands moving VM files into hidden directories→ DC0064 Command ExecutionTunable:VMFileScopeAN1388 Office SuiteMalicious macros or embedded objects hidden within Office documents by renaming streams or using hidden OLE objects. Defender view: detection of hidden macro streams or objects in documents correlated with anomalous execution.m365:unifiedDetection of hidden macro streams or SetHiddenAttribute actions→ DC0038 Application Log ContentTunable:MacroScope
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1564
Author: frack113
· 2021-06-04 (modified 2022-08-02) · logsource: product=windows category=sysmon_status · 1f2b5353-573f-4880-8e33-7d04dcf97744
Detects when an attacker tries to hide from Sysmon by disabling or stopping it
Author: Tobias Michalski (Nextron Systems)
· 2022-02-24 (modified 2023-08-17) · logsource: product=windows category=registry_set · 2ff692c2-4594-41ec-8fcb-46587de769e0
Detects disabling the CrashDump per registry (as used by HermeticWiper)
Author: Florian Roth (Nextron Systems)
· 2023-05-08 (modified 2024-11-23) · logsource: product=windows category=process_creation · 5722dff1-4bdd-4949-86ab-fbaf707e767a
Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2022-02-25 (modified 2024-07-12) · logsource: product=windows category=process_creation · 69bd9b97-2be2-41b6-9816-fb08757a4d1a
Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
Author: frack113
· 2022-09-05 (modified 2023-12-11) · logsource: product=windows category=file_event · 74babdd6-a758-4549-9632-26535279e654
Detect creation of suspicious executable file names.
Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
Author: Florian Roth (Nextron Systems)
· 2022-10-10 (modified 2024-11-23) · logsource: product=windows category=process_creation · 811e0002-b13b-4a15-9d00-a613fce66e42
Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc).
Process Hacker is a tool to view and manipulate processes, kernel options and other low level options.
Threat actors abused older vulnerable versions to manipulate system processes.
Author: frack113
· 2021-06-04 (modified 2026-07-23) · logsource: product=windows category=sysmon_error · 815cd91b-7dbc-4247-841a-d7dd1392b0a8
Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages
Author: Janantha Marasinghe
· 2020-09-26 (modified 2025-07-29) · logsource: product=windows category=process_creation · bab049ca-7471-4828-9024-38279a4c04da
Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
Author: frack113
· 2022-01-21 (modified 2023-01-05) · logsource: product=windows category=file_event · e15b518d-b4ce-4410-a9cd-501f23ce4a18
Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
· 2023-01-12 · logsource: product=linux category=process_creation · ec52985a-d024-41e3-8ff6-14169039a0b3
Detects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system
Sub-techniques
| ID | Name | Sigma rules | KEV CVEs |
|---|---|---|---|
| T1564.001 | Hidden Files and Directories | 9 | 0 |
| T1564.002 | Hidden Users | 4 | 0 |
| T1564.003 | Hidden Window | 8 | 0 |
| T1564.004 | NTFS File Attributes | 23 | 0 |
| T1564.005 | Hidden File System | 0 | 0 |
| T1564.006 | Run Virtual Instance | 2 | 0 |
| T1564.007 | VBA Stomping | 0 | 0 |
| T1564.008 | Email Hiding Rules | 4 | 0 |
| T1564.009 | Resource Forking | 0 | 0 |
| T1564.010 | Process Argument Spoofing | 0 | 0 |
| T1564.011 | Ignore Process Interrupts | 0 | 0 |
| T1564.012 | File/Path Exclusions | 0 | 0 |
| T1564.013 | Bind Mounts | 0 | 0 |
| T1564.014 | Extended Attributes | 0 | 0 |