{"id":"T1564","name":"Hide Artifacts","url":"https://attack.mitre.org/techniques/T1564","tactics":["stealth"],"platforms":["ESXi","Linux","macOS","Office Suite","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0502","stix_id":"x-mitre-detection-strategy--bd2348f8-acef-4310-bd03-cf7b866d2592","name":"Detection Strategy for Hidden Artifacts Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0502","analytics":[{"id":"AN1384","stix_id":"x-mitre-analytic--e01b29cd-2369-4ad5-bd91-98994f36cd1e","name":"Analytic 1384","description":"Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.","url":"https://attack.mitre.org/detectionstrategies/DET0502#AN1384","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"FileExtensions","description":"Filter for sensitive file types likely targeted for hiding."},{"field":"ADSDetection","description":"Enable or disable detection of Alternate Data Streams depending on business use."}],"live":true,"detection_strategies":["DET0502"],"techniques":["T1564"]},{"id":"AN1385","stix_id":"x-mitre-analytic--2c3ec402-b9e9-4091-a04d-3b73f260e669","name":"Analytic 1385","description":"Hidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories.","url":"https://attack.mitre.org/detectionstrategies/DET0502#AN1385","platforms":["Linux"],"log_source_references":[{"name":"auditd:EXECVE","channel":"Execution of chattr to set +i or +a attributes","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-execve"},{"name":"auditd:FILE","channel":"Creation of hidden files (.*) in sensitive directories (/etc, /var, /usr/bin)","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-file"}],"mutable_elements":[{"field":"DirectoryScope","description":"Restrict hidden file detection to privileged system directories."},{"field":"AttributeFlags","description":"Tune for specific chattr flags (+i immutable, +a append-only) most abused for persistence."}],"live":true,"detection_strategies":["DET0502"],"techniques":["T1564"]},{"id":"AN1386","stix_id":"x-mitre-analytic--8963772e-2ee5-421e-aec0-b952d05d4efc","name":"Analytic 1386","description":"Hidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths.","url":"https://attack.mitre.org/detectionstrategies/DET0502#AN1386","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of chflags hidden or setfile -a V","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Creation of LaunchAgents/LaunchDaemons in hidden or non-standard directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"HiddenDirectories","description":"List of directories monitored for hidden plist or agent placement."}],"live":true,"detection_strategies":["DET0502"],"techniques":["T1564"]},{"id":"AN1387","stix_id":"x-mitre-analytic--a3c087a6-b7dc-464f-9e84-278bf3076ed1","name":"Analytic 1387","description":"Abuse of VMFS or ESXi shell to hide datastore files, renaming/moving VMDK or VMX files into hidden directories. Defender view: anomalous ESXi shell commands or file operations obscuring VM artifacts.","url":"https://attack.mitre.org/detectionstrategies/DET0502#AN1387","platforms":["ESXi"],"log_source_references":[{"name":"esxi:shell","channel":"mv, rename, or chmod commands moving VM files into hidden directories","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-shell"},{"name":"esxi:syslog","channel":"Datastore file hidden or renamed unexpectedly","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"esxi-syslog"}],"mutable_elements":[{"field":"VMFileScope","description":"Restrict to VMDK, VMX, or log files critical for VM operations."}],"live":true,"detection_strategies":["DET0502"],"techniques":["T1564"]},{"id":"AN1388","stix_id":"x-mitre-analytic--a6299804-cf50-4496-a242-1394ff89c147","name":"Analytic 1388","description":"Malicious macros or embedded objects hidden within Office documents by renaming streams or using hidden OLE objects. Defender view: detection of hidden macro streams or objects in documents correlated with anomalous execution.","url":"https://attack.mitre.org/detectionstrategies/DET0502#AN1388","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Detection of hidden macro streams or SetHiddenAttribute actions","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"MacroScope","description":"Tune detection to specific Office apps and document types where macros are disallowed."}],"live":true,"detection_strategies":["DET0502"],"techniques":["T1564"]}],"live":true,"version":"1.0","techniques":["T1564"]}],"sigma_rules":[{"id":"1f2b5353-573f-4880-8e33-7d04dcf97744","title":"Sysmon Configuration Modification","author":"frack113","status":"test","level":"high","date":"2021-06-04","modified":"2022-08-02","description":"Detects when an attacker tries to hide from Sysmon by disabling or stopping it","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://talesfrominfosec.blogspot.com/2017/12/killing-sysmon-silently.html"],"logsource":{"product":"windows","category":"sysmon_status"},"tags":["attack.stealth","attack.t1564"],"path":"rules/windows/sysmon/sysmon_config_modification_status.yml","techniques":["T1564"],"cves":[]},{"id":"2ff692c2-4594-41ec-8fcb-46587de769e0","title":"CrashControl CrashDump Disabled","author":"Tobias Michalski (Nextron Systems)","status":"test","level":"medium","date":"2022-02-24","modified":"2023-08-17","description":"Detects disabling the CrashDump per registry (as used by HermeticWiper)","references":["https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.stealth","attack.defense-impairment","attack.t1564","attack.t1112"],"path":"rules/windows/registry/registry_set/registry_set_crashdump_disabled.yml","techniques":["T1564","T1112"],"cves":[]},{"id":"5722dff1-4bdd-4949-86ab-fbaf707e767a","title":"PUA - System Informer Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2023-05-08","modified":"2024-11-23","description":"Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations","references":["https://github.com/winsiderss/systeminformer"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.discovery","attack.stealth","attack.t1082","attack.t1564","attack.t1543"],"path":"rules/windows/process_creation/proc_creation_win_pua_system_informer.yml","techniques":["T1082","T1564","T1543"],"cves":[]},{"id":"69bd9b97-2be2-41b6-9816-fb08757a4d1a","title":"Potentially Suspicious Execution From Parent Process In Public Folder","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":"2024-07-12","description":"Detects a potentially suspicious execution of a parent process located in the \"\\Users\\Public\" folder executing a child process containing references to shell or scripting binaries and commandlines.\n","references":["https://redcanary.com/blog/blackbyte-ransomware/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1564","attack.t1059"],"path":"rules/windows/process_creation/proc_creation_win_susp_execution_from_public_folder_as_parent.yml","techniques":["T1564","T1059"],"cves":[]},{"id":"74babdd6-a758-4549-9632-26535279e654","title":"Suspicious Executable File Creation","author":"frack113","status":"test","level":"high","date":"2022-09-05","modified":"2023-12-11","description":"Detect creation of suspicious executable file names.\nSome strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.\n","references":["https://medium.com/@SumitVerma101/windows-privilege-escalation-part-1-unquoted-service-path-c7a011a8d8ae","https://app.any.run/tasks/76c69e2d-01e8-49d9-9aea-fb7cc0c4d3ad/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1564"],"path":"rules/windows/file/file_event/file_event_win_susp_executable_creation.yml","techniques":["T1564"],"cves":[]},{"id":"811e0002-b13b-4a15-9d00-a613fce66e42","title":"PUA - Process Hacker Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-10-10","modified":"2024-11-23","description":"Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc).\nProcess Hacker is a tool to view and manipulate processes, kernel options and other low level options.\nThreat actors abused older vulnerable versions to manipulate system processes.\n","references":["https://processhacker.sourceforge.io/","https://www.crowdstrike.com/blog/falcon-overwatch-report-finds-increase-in-ecrime/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.persistence","attack.privilege-escalation","attack.stealth","attack.t1622","attack.t1564","attack.t1543"],"path":"rules/windows/process_creation/proc_creation_win_pua_process_hacker.yml","techniques":["T1622","T1564","T1543"],"cves":[]},{"id":"815cd91b-7dbc-4247-841a-d7dd1392b0a8","title":"Sysmon Configuration Error","author":"frack113","status":"test","level":"high","date":"2021-06-04","modified":"2026-07-23","description":"Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md","https://talesfrominfosec.blogspot.com/2017/12/killing-sysmon-silently.html"],"logsource":{"product":"windows","category":"sysmon_error"},"tags":["attack.stealth","attack.t1564"],"path":"rules/windows/sysmon/sysmon_config_modification_error.yml","techniques":["T1564"],"cves":[]},{"id":"bab049ca-7471-4828-9024-38279a4c04da","title":"Virtualbox Driver Installation or Starting of VMs","author":"Janantha Marasinghe","status":"test","level":"low","date":"2020-09-26","modified":"2025-07-29","description":"Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.","references":["https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/","https://threatpost.com/maze-ransomware-ragnar-locker-virtual-machine/159350/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1564.006","attack.t1564"],"path":"rules/windows/process_creation/proc_creation_win_virtualbox_execution.yml","techniques":["T1564.006","T1564"],"cves":[]},{"id":"e15b518d-b4ce-4410-a9cd-501f23ce4a18","title":"Suspicious Creation with Colorcpl","author":"frack113","status":"test","level":"high","date":"2022-01-21","modified":"2023-01-05","description":"Once executed, colorcpl.exe will copy the arbitrary file to c:\\windows\\system32\\spool\\drivers\\color\\","references":["https://twitter.com/eral4m/status/1480468728324231172?s=20"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1564"],"path":"rules/windows/file/file_event/file_event_win_susp_colorcpl.yml","techniques":["T1564"],"cves":[]},{"id":"ec52985a-d024-41e3-8ff6-14169039a0b3","title":"Mount Execution With Hidepid Parameter","author":"Joseliyo Sanchez, @Joseliyo_Jstnk","status":"test","level":"medium","date":"2023-01-12","modified":null,"description":"Detects execution of the \"mount\" command with \"hidepid\" parameter to make invisible processes to other users from the system","references":["https://blogs.blackberry.com/","https://www.cyberciti.biz/faq/linux-hide-processes-from-other-users/","https://twitter.com/Joseliyo_Jstnk/status/1620131033474822144"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.credential-access","attack.stealth","attack.t1564"],"path":"rules/linux/process_creation/proc_creation_lnx_mount_hidepid.yml","techniques":["T1564"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}