{"id":"T1027.011","name":"Fileless Storage","url":"https://attack.mitre.org/techniques/T1027/011","tactics":["stealth"],"platforms":["Linux","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0344","stix_id":"x-mitre-detection-strategy--aea09aae-c0c3-4453-aa44-ea0153e5cb8c","name":"Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory","url":"https://attack.mitre.org/detectionstrategies/DET0344","analytics":[{"id":"AN0973","stix_id":"x-mitre-analytic--4f5f4b26-0bf0-4f3d-b8ac-1af660923bd2","name":"Analytic 0973","description":"Detects abuse of fileless storage mechanisms such as Registry keys, WMI classes, and Event Logs used to stage payloads, scripts, or encoded content outside traditional files.","url":"https://attack.mitre.org/detectionstrategies/DET0344#AN0973","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4657","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Application","channel":"WMI Object Creation Events","data_component":"DC0008","data_component_name":"WMI Creation","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"RegistryPathFilter","description":"Scoped to suspicious or abused paths like HKCU\\Software\\Classes\\ or HKLM\\SYSTEM\\CurrentControlSet\\Services\\"},{"field":"PayloadEntropyThreshold","description":"Minimum entropy level to flag suspicious registry or WMI content as encoded payloads"},{"field":"TimeWindow","description":"Temporal window for correlating WMI/registry modifications with process creation or network usage"}],"live":true,"detection_strategies":["DET0344"],"techniques":["T1027.011"]},{"id":"AN0974","stix_id":"x-mitre-analytic--b521510b-83bc-46a2-8fc8-65a6975bcfca","name":"Analytic 0974","description":"Detects usage of shared memory directories (/dev/shm, /run/shm) for temporary storage of obfuscated, encoded, or executable data without persistence to disk.","url":"https://attack.mitre.org/detectionstrategies/DET0344#AN0974","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, write, unlink","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"file_events.path","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"PathPrefix","description":"Shared memory mount path used (e.g., /dev/shm/ or /run/shm/)"},{"field":"FilenameRegex","description":"Regex to match non-standard, suspicious, or encoded filenames"},{"field":"ExecCorrelationWindow","description":"Time window to correlate process execution from shared memory directories"}],"live":true,"detection_strategies":["DET0344"],"techniques":["T1027.011"]}],"live":true,"version":"1.0","techniques":["T1027.011"]}],"sigma_rules":[{"id":"5cd16c8f-44a6-4654-81e7-a84d6db507d4","title":"Process Execution From Shared Memory Directory","author":"Stan Beukers","status":"experimental","level":"high","date":"2026-06-20","modified":null,"description":"Detects the execution of a binary from the Linux shared memory directory /dev/shm.\nThis directory is a tmpfs mount backed entirely by RAM and is abused by attackers for fileless malware staging because files written there never touch physical disk and may evade disk-based detection.\n","references":["https://www.sysdig.com/blog/containers-read-only-fileless-malware","https://unfinished.bike/fun-with-the-new-bpfdoor-2023","https://asiapacificdefencereporter.com/wp-content/uploads/2023/08/Final-CRWD-2023-Threat-Hunting-Report.pdf","https://www.crowdstrike.com/en-us/blog/how-to-hunt-for-decisivearchitect-and-justforfun-implant/","https://www.linkedin.com/posts/avradeep_malware-apt-infostealer-activity-7373203959697719296-JR-7","https://www.stormshield.com/news/orbit-analysis-of-a-linux-dedicated-malware/"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.stealth","attack.execution","attack.t1027.011"],"path":"rules/linux/process_creation/proc_creation_lnx_susp_exec_from_dev_shm.yml","techniques":["T1027.011"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}