1200KM / detection
T1564.003 Hidden Window — Detection Rules
Detection workspace for T1564.003 Hidden Window: 8 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious PowerShell WindowStyle Option · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Potential Data Stealing Via Chromium Headless Debugging · test · high · {"category":"process_creation","product":"windows"}
- Browser Execution In Headless Mode · test · low · {"category":"process_creation","product":"windows"}
- File Download with Headless Browser · test · high · {"category":"process_creation","product":"windows"}
- Cmd Launched with Hidden Start Flags to Suspicious Targets · experimental · medium · {"category":"process_creation","product":"windows"}
- Powershell Executed From Headless ConHost Process · test · medium · {"category":"process_creation","product":"windows"}
- HackTool - Covenant PowerShell Launcher · test · high · {"category":"process_creation","product":"windows"}
- PUA - AdvancedRun Execution · test · medium · {"product":"windows","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0128 Detection Strategy for Hidden Windows
AN0360 Analytic 0360
Suspicious use of scripting parameters or registry edits to hide process windows (e.g., powershell.exe -WindowStyle Hidden, or registry modifications pushing window positions off screen). Defender view: correlation of hidden execution with anomalous process lineage or hVNC-like CreateDesktop API calls.
AN0361 Analytic 0361
Suspicious invocation of GUI utilities or scripts with suppressed or redirected windowing options. Defender view: detection of X11 or Wayland calls to spawn windows that do not appear on active displays, or use of nohup/screen/tmux to mask interactive shells.
AN0362 Analytic 0362
Modification of plist files to set apple.awt.UIElement or similar flags hiding app icons and windows, and dscl/command-line activity that suppresses visibility. Defender view: correlation of plist modifications with unexpected hidden user applications.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Deep Panda · G0009
- APT3 · G0022
- FIN7 · G0046
- Gamaredon Group · G0047
- APT32 · G0050
- CopyKittens · G0052
- Magic Hound · G0059
- APT19 · G0073
- Gorgon Group · G0078
- DarkHydrus · G0079
- Kimsuky · G0094
- APT-C-36 · G0099
- Higaisa · G0126
- Nomadic Octopus · G0133
- ToddyCat · G1022
- Medusa Group · G1051
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.