1200KM / detection
T1027.013 Encrypted/Encoded File — Detection Rules
Detection workspace for T1027.013 Encrypted/Encoded File: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0087 Encrypted or Encoded File Payload Detection Strategy
AN0237 Analytic 0237
Detection of processes that load or decode encrypted/encoded files in memory and subsequently execute or inject them, indicating payload unpacking or memory-resident malware.
AN0238 Analytic 0238
Detection of suspicious use of shell utilities or scripts that decode or decrypt a payload and execute it without writing to disk.
AN0239 Analytic 0239
Detection of encoded payloads being decoded and executed in-memory using scripting tools or third-party decoders.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Darkhotel · G0012
- Putter Panda · G0024
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Group5 · G0043
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- Dark Caracal · G0070
- APT19 · G0073
- Tropic Trooper · G0081
- APT39 · G0087
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Inception · G0100
- Mofang · G0103
- Whitefly · G0107
- Blue Mockingbird · G0108
- Fox Kitten · G0117
- Sidewinder · G0121
- Higaisa · G0126
- Transparent Tribe · G0134
- TeamTNT · G0139
- BITTER · G1002
- Moses Staff · G1009
- Metador · G1013
- TA2541 · G1018
- Malteiro · G1026
- Saint Bear · G1031
- Moonstone Sleet · G1036
- Storm-1811 · G1046
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.