{"id":"T1027.002","name":"Software Packing","url":"https://attack.mitre.org/techniques/T1027/002","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0023","stix_id":"x-mitre-detection-strategy--7a182af0-a7e1-41a1-ae5e-ac76ff7f5948","name":"Obfuscated Binary Unpacking Detection via Behavioral Patterns","url":"https://attack.mitre.org/detectionstrategies/DET0023","analytics":[{"id":"AN0066","stix_id":"x-mitre-analytic--e6a7eeb3-0652-460c-b68b-f17d2ed82822","name":"Analytic 0066","description":"Detection of unpacking behavior through abnormal memory allocation, followed by executable code injection and execution from non-image sections.","url":"https://attack.mitre.org/detectionstrategies/DET0023#AN0066","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"To scope detections to suspicious parent-child process relationships typical of loaders or droppers."},{"field":"AllocationSizeThreshold","description":"To tune for unusually large virtual memory allocations that might indicate unpacked payloads."}],"live":true,"detection_strategies":["DET0023"],"techniques":["T1027.002"]},{"id":"AN0067","stix_id":"x-mitre-analytic--3cb4d3f4-df71-474c-a9f0-438dbf26bf66","name":"Analytic 0067","description":"Correlates ELF file execution with high-entropy writable memory segments and self-modifying code patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0023#AN0067","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"mprotect","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"EntropyThreshold","description":"Useful for tuning unpacked sections containing high entropy indicative of compression or encryption."},{"field":"TimeWindow","description":"Can be tuned to correlate file writes to execution within a set timeframe."}],"live":true,"detection_strategies":["DET0023"],"techniques":["T1027.002"]},{"id":"AN0068","stix_id":"x-mitre-analytic--003c2ca3-a9a8-4a56-9163-f6733f19b41d","name":"Analytic 0068","description":"Detection of packed Mach-O binaries unpacking into memory and transferring control to dynamically modified code segments.","url":"https://attack.mitre.org/detectionstrategies/DET0023#AN0068","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process::exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_MMAP","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"SignedBinaryContext","description":"Helps to distinguish between signed/unsigned packed binaries (common in legitimate vs. malicious cases)."},{"field":"UserContext","description":"Can be used to scope to specific users or service accounts targeted in attacks."}],"live":true,"detection_strategies":["DET0023"],"techniques":["T1027.002"]}],"live":true,"version":"1.0","techniques":["T1027.002"]}],"sigma_rules":[{"id":"cbb56d62-4060-40f7-9466-d8aaf3123f83","title":"Python Image Load By Non-Python Process","author":"Patrick St. John, OTR (Open Threat Research)","status":"test","level":"low","date":"2020-05-03","modified":"2025-08-18","description":"Detects the image load of \"Python Core\" by a non-Python process. This might be indicative of a execution of executable that has been bundled from Python code.\nVarious tools like Py2Exe, PyInstaller, and cx_Freeze are used to bundle Python code into standalone executables.\nThreat actors often use these tools to bundle malicious Python scripts into executables, sometimes to obfuscate the code or to bypass security measures.\n","references":["https://www.py2exe.org/","https://unit42.paloaltonetworks.com/unit-42-technical-analysis-seaduke/"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.stealth","attack.t1027.002"],"path":"rules/windows/image_load/image_load_susp_python_image_load.yml","techniques":["T1027.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}