{"id":"T1027.016","name":"Junk Code Insertion","url":"https://attack.mitre.org/techniques/T1027/016","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0322","stix_id":"x-mitre-detection-strategy--206790b2-16bc-46db-a605-8bcff576c161","name":"Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns","url":"https://attack.mitre.org/detectionstrategies/DET0322","analytics":[{"id":"AN0913","stix_id":"x-mitre-analytic--2ae1dd34-c666-488f-8ad6-752b8a6acae1","name":"Analytic 0913","description":"Detects the presence of executables with high NOP padding, unusually large binary size for their function, and follow-on execution or memory injection from such files, especially when originating from temp or user-space paths.","url":"https://attack.mitre.org/detectionstrategies/DET0322#AN0913","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=10","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"NOPThreshold","description":"High proportion of 0x90 opcodes indicating junk code – tune to suppress noise from some packing tools"},{"field":"ExecutableSizeThreshold","description":"Size range for abnormally large binaries relative to their runtime behavior"},{"field":"TimeWindow","description":"Window between file creation and execution – short intervals may indicate staged payload execution"}],"live":true,"detection_strategies":["DET0322"],"techniques":["T1027.016"]},{"id":"AN0914","stix_id":"x-mitre-analytic--f606ec01-15d2-4432-b91b-669411205015","name":"Analytic 0914","description":"Detects ELF binaries written to disk that demonstrate anomalous file size or entropy, quickly followed by execution or memory region writes into remote processes (e.g., using ptrace).","url":"https://attack.mitre.org/detectionstrategies/DET0322#AN0914","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"SYSCALL ptrace/mprotect","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"BinarySizeThreshold","description":"Used to flag binaries much larger than typical shell utilities or payloads"},{"field":"MemoryWriteTargets","description":"Which processes are allowed ptrace/mprotect – can limit to suspicious child-to-parent targeting"},{"field":"ExecutionAfterWriteWindow","description":"Temporal threshold for file write to execution"}],"live":true,"detection_strategies":["DET0322"],"techniques":["T1027.016"]},{"id":"AN0915","stix_id":"x-mitre-analytic--fcc2b0dc-93c4-49de-abfe-6273c24d1d89","name":"Analytic 0915","description":"Identifies Mach-O binaries dropped into temporary directories with abnormally high binary size or padding patterns, followed by privilege escalation, `exec`, or memory mapping of other processes.","url":"https://attack.mitre.org/detectionstrategies/DET0322#AN0915","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_MMAP","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"macos-endpointsecurity"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_OPEN","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"macos-endpointsecurity"}],"mutable_elements":[{"field":"TempFilePaths","description":"Track dropped executables in ~/Library/, /tmp/, or /private/tmp/"},{"field":"MachOPaddingThreshold","description":"Define padding size or section entropy anomalies in Mach-O file format"},{"field":"FollowOnPrivilegeEscalation","description":"Detects whether the binary attempts privilege escalation within short execution window"}],"live":true,"detection_strategies":["DET0322"],"techniques":["T1027.016"]}],"live":true,"version":"1.0","techniques":["T1027.016"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}