1200KM / detection
T1027.014 Polymorphic Code — Detection Rules
Detection workspace for T1027.014 Polymorphic Code: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0324 Detection Strategy for Polymorphic Code Mutation and Execution
AN0919 Analytic 0919
Identifies self-modifying executables that exhibit changes in binary hash, entropy, or memory sections during or between executions—often tied to dynamic unpacking or decryption behaviors.
AN0920 Analytic 0920
Detects files or processes where execution results in frequent re-creation or modification of ELF binaries or interpreter scripts, often using chmod + execve with abnormal entropy.
AN0921 Analytic 0921
Tracks modification of executables or interpreter payloads (e.g., Mach-O, dylib) that mutate across runs—using scripting engines, JIT compilers, or side-loaded plugins.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1027.014 simulation workspace
- File Creation · DC0039
- File Modification · DC0061
- Module Load · DC0016
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.