1200KM / detection
T1027.003 Steganography — Detection Rules
Detection workspace for T1027.003 Steganography: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Steganography Hide Zip Information in Picture File · test · low · {"product":"linux","service":"auditd"}
- Steganography Hide Files with Steghide · test · low · {"product":"linux","service":"auditd"}
- Steganography Extract Files with Steghide · test · low · {"product":"linux","service":"auditd"}
- Steganography Unzip Hidden Information From Picture File · test · low · {"product":"linux","service":"auditd"}
- Findstr Launching .lnk File · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0119 Detection Strategy for Steganographic Abuse in File & Script Execution
AN0331 Analytic 0331
Detects execution of image viewers or PowerShell scripts accessing or decoding files with mismatched MIME headers or embedded script-like byte patterns; often correlated with suspicious parent-child process lineage and outbound connections.
AN0332 Analytic 0332
Detects access to media files followed by execution of scripts (bash, Python, etc.) referencing those same files, or outbound traffic triggered shortly after file read. Correlates unusual use of tools like `steghide`, `exiftool`, or image libraries.
AN0333 Analytic 0333
Detects manipulation of PNG, JPG, or GIF files by user-initiated scripts followed by script execution or exfiltration behavior, especially from `osascript`, `python`, or `bash`, in combination with LaunchAgent persistence or curl activity.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.