1200KM / detection
T1027.001 Binary Padding — Detection Rules
Detection workspace for T1027.001 Binary Padding: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Binary Padding - Linux · test · high · {"product":"linux","service":"auditd"}
- Binary Padding - MacOS · test · high · {"product":"macos","category":"process_creation"}
- Failed Code Integrity Checks · stable · informational · {"product":"windows","service":"security"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0553 Detection Strategy for Obfuscated Files or Information: Binary Padding
AN1528 Analytic 1528
Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host.
AN1529 Analytic 1529
Detects abnormal creation of binary files with significant size that are subsequently executed or accessed by non-standard users.
AN1530 Analytic 1530
Monitors for anomalous binary files written to disk with padded size and subsequent execution by user or service context.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1027.001 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.