1200KM / detection
T1140 Deobfuscate/Decode Files or Information — Detection Rules
Detection workspace for T1140 Deobfuscate/Decode Files or Information: 14 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Inbox Manipulation Rules · test · high · {"product":"azure","service":"riskdetection"}
- Linux Base64 Encoded Pipe to Shell · test · medium · {"product":"linux","category":"process_creation"}
- Linux Base64 Encoded Shebang In CLI · test · medium · {"product":"linux","category":"process_creation"}
- Linux Shell Pipe to Shell · test · medium · {"product":"linux","category":"process_creation"}
- Payload Decoded and Decrypted via Built-in Utilities · test · medium · {"category":"process_creation","product":"macos"}
- Potential Base64 Decoded From Images · test · high · {"product":"macos","category":"process_creation"}
- PowerShell Decompress Commands · test · informational · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- MSHTA Execution with Suspicious File Extensions · test · high · {"category":"process_creation","product":"windows"}
- Ping Hex IP · test · high · {"category":"process_creation","product":"windows"}
- PowerShell Base64 Encoded FromBase64String Cmdlet · test · high · {"category":"process_creation","product":"windows"}
- Base64 Encoded PowerShell Command Detected · test · high · {"category":"process_creation","product":"windows"}
- Suspicious XOR Encoded PowerShell Command · test · medium · {"category":"process_creation","product":"windows"}
- Potential Commandline Obfuscation Using Escape Characters · test · medium · {"category":"process_creation","product":"windows"}
- DNS-over-HTTPS Enabled by Registry · test · medium · {"product":"windows","category":"registry_set"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0275 Detect Adversary Deobfuscation or Decoding of Files and Payloads
AN0767 Analytic 0767
An adversary leverages built-in tools such as certutil.exe, powershell.exe, or copy.exe to decode, reassemble, or extract hidden malicious content from obfuscated containers or encoded formats. The decoding utility often spawns shortly after file staging or download and may be chained with script interpreters or further payload execution.
AN0768 Analytic 0768
The adversary uses native utilities like base64, gzip, tar, or openssl to decode, decompress, or decrypt files that were previously staged or downloaded. These tools may be chained with curl/wget and executed via bash/zsh, often to extract an embedded payload or reverse shell script.
AN0769 Analytic 0769
The adversary invokes built-in scripting or decoding tools like base64, plutil, or AppleScript-based utilities to decode files embedded in staging artifacts. Decoding often occurs post-download or as part of post-exploitation payload deployment via zsh, python, or osascript.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- Molerats · G0021
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- BRONZE BUTLER · G0060
- Leviathan · G0065
- MuddyWater · G0069
- APT19 · G0073
- Gorgon Group · G0078
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- WIRTE · G0090
- TA505 · G0092
- Kimsuky · G0094
- Rocke · G0106
- Higaisa · G0126
- ZIRCONIUM · G0128
- Mustang Panda · G0129
- TeamTNT · G0139
- Earth Lusca · G1006
- FIN13 · G1016
- Volt Typhoon · G1017
- Cinnamon Tempest · G1021
- Malteiro · G1026
- Agrius · G1030
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- BlackByte · G1043
- Storm-1811 · G1046
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.