{"id":"T1564.014","name":"Extended Attributes","url":"https://attack.mitre.org/techniques/T1564/014","tactics":["stealth"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0406","stix_id":"x-mitre-detection-strategy--e32dbff1-9d06-4495-b815-48463481581b","name":"Detection Strategy for Extended Attributes Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0406","analytics":[{"id":"AN1135","stix_id":"x-mitre-analytic--f398e8ff-8c61-4672-8ace-118b11a38515","name":"Analytic 1135","description":"Abuse of extended attributes (xattrs) to embed hidden payloads into legitimate files. Defender perspective: detect anomalous use of setfattr or getfattr commands, or direct syscalls (setxattr, getxattr) where attributes are unusually large or contain encoded data. Behavior chain includes: (1) execution of setfattr with suspicious namespaces (user., trusted.), (2) file metadata modification inconsistent with file size/hash, and (3) subsequent process execution reading attributes followed by decoding activity.","url":"https://attack.mitre.org/detectionstrategies/DET0406#AN1135","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"setxattr or getxattr system call","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"execution of setfattr or getfattr commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"}],"mutable_elements":[{"field":"XattrNamespaces","description":"Namespaces monitored for suspicious activity (user., trusted., security.). Organizations may tune to reduce noise from benign use."},{"field":"PayloadSizeThreshold","description":"Size of xattr values above which they should be considered anomalous (e.g., >1KB)."},{"field":"CorrelationWindow","description":"Time window to correlate xattr modification with process execution from the same file."}],"live":true,"detection_strategies":["DET0406"],"techniques":["T1564.014"]},{"id":"AN1136","stix_id":"x-mitre-analytic--f5a0dc9d-3dda-4e31-ad4d-0560b918b6b1","name":"Analytic 1136","description":"Abuse of extended attributes (xattrs) to hide payloads in com.apple.* or custom keys. Defender perspective: monitor suspicious use of xattr command with -w (write) and -p (print) flags, especially when followed by execution of interpreters like bash, Python, or osascript. Behavior chain includes: (1) suspicious file modification with new com.apple.* attributes, (2) attribute content inconsistent with expected metadata tags (e.g., high entropy), (3) subsequent process execution correlated with extraction of the attribute.","url":"https://attack.mitre.org/detectionstrategies/DET0406#AN1136","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"xattr utility execution with -w or -p flags","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"extended attribute write or modification","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"WatchedXattrKeys","description":"Specific xattr keys to monitor (e.g., com.apple.quarantine, com.apple.ResourceFork, unknown custom keys)."},{"field":"EntropyThreshold","description":"High entropy attribute values may indicate encoded or encrypted payloads."},{"field":"ProcessContext","description":"Expected legitimate applications interacting with xattrs (Finder, Spotlight) to help reduce false positives."}],"live":true,"detection_strategies":["DET0406"],"techniques":["T1564.014"]}],"live":true,"version":"1.0","techniques":["T1564.014"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}