{"id":"T1027.009","name":"Embedded Payloads","url":"https://attack.mitre.org/techniques/T1027/009","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0214","stix_id":"x-mitre-detection-strategy--99294309-83fd-46f3-9925-7443c03e5b79","name":"Detection Strategy for Embedded Payloads","url":"https://attack.mitre.org/detectionstrategies/DET0214","analytics":[{"id":"AN0599","stix_id":"x-mitre-analytic--8f84fc52-ab74-443b-b618-aa1c0941377a","name":"Analytic 0599","description":"Detection of executables or scripts containing hidden embedded resources or secondary payloads, often with anomalies in file size vs. functionality or dropped child binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0214#AN0599","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"EDR:file","channel":"File Metadata Analysis (PE overlays, entropy)","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"edr-file"}],"mutable_elements":[{"field":"OverlaySizeThreshold","description":"Threshold in bytes where appended sections to binaries are considered suspicious"},{"field":"ProcessTreeDepth","description":"Controls how far child process lineage is analyzed for dropped embedded payloads"},{"field":"TimeWindow","description":"Defines correlation interval between file write and process execution"}],"live":true,"detection_strategies":["DET0214"],"techniques":["T1027.009"]},{"id":"AN0600","stix_id":"x-mitre-analytic--db9b55b0-7e54-4625-92d5-fbe9ed8ac868","name":"Analytic 0600","description":"Detection of shell scripts, ELF binaries, or archives containing embedded secondary payloads, self-extracting components, or unusual compression behavior during runtime.","url":"https://attack.mitre.org/detectionstrategies/DET0214#AN0600","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"elf_info, hash, yara_matches","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"},{"name":"ebpf:syscalls","channel":"container_file_activity","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"ebpf-syscalls"}],"mutable_elements":[{"field":"FileSectionCount","description":"Tuning value for ELF binaries with appended sections or resources"},{"field":"ScriptLength","description":"Threshold for long shell scripts with base64-encoded binary content"},{"field":"ExtractedFileCount","description":"Number of files written from a single script execution"}],"live":true,"detection_strategies":["DET0214"],"techniques":["T1027.009"]},{"id":"AN0601","stix_id":"x-mitre-analytic--8cd6ae3d-7f14-42bf-9aff-870209fc333f","name":"Analytic 0601","description":"Detection of Mach-O binaries or AppleScripts that contain nested, encoded, or run-only embedded payloads dropped at runtime.","url":"https://attack.mitre.org/detectionstrategies/DET0214#AN0601","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"logd:file write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:osquery","channel":"mach_o_info, file_metadata","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-osquery"}],"mutable_elements":[{"field":"ScriptFormatType","description":"Run-only AppleScripts or signed scripting payloads may require scoped detection"},{"field":"DroppedBinaryCount","description":"Threshold on number of binaries created by the parent payload"},{"field":"ParentProcessName","description":"Allows focusing on suspicious interpreter or staging tools"}],"live":true,"detection_strategies":["DET0214"],"techniques":["T1027.009"]}],"live":true,"version":"1.0","techniques":["T1027.009"]}],"sigma_rules":[{"id":"deb9b646-a508-44ee-b7c9-d8965921c6b6","title":"Powershell Token Obfuscation - Process Creation","author":"frack113","status":"test","level":"high","date":"2022-12-27","modified":"2026-03-16","description":"Detects TOKEN OBFUSCATION technique from Invoke-Obfuscation","references":["https://github.com/danielbohannon/Invoke-Obfuscation"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1027.009"],"path":"rules/windows/process_creation/proc_creation_win_powershell_token_obfuscation.yml","techniques":["T1027.009"],"cves":[]},{"id":"f3a98ce4-6164-4dd4-867c-4d83de7eca51","title":"Powershell Token Obfuscation - Powershell","author":"frack113","status":"test","level":"medium","date":"2022-12-27","modified":"2025-10-19","description":"Detects TOKEN OBFUSCATION technique from Invoke-Obfuscation in Powershell scripts.\nUse this rule as a threat-hunting baseline to find obfuscated scripts in your environment.\nOnce tested and tuned, consider deploying a production detection rule based on this hunting rule.\n","references":["https://github.com/danielbohannon/Invoke-Obfuscation"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.stealth","attack.t1027.009","detection.threat-hunting"],"path":"rules-threat-hunting/windows/powershell/powershell_script/posh_ps_token_obfuscation.yml","techniques":["T1027.009"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}