1200KM / detection
T1564 Hide Artifacts — Detection Rules
Detection workspace for T1564 Hide Artifacts: 10 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Mount Execution With Hidepid Parameter · test · medium · {"product":"linux","category":"process_creation"}
- Suspicious Creation with Colorcpl · test · high · {"product":"windows","category":"file_event"}
- Suspicious Executable File Creation · test · high · {"product":"windows","category":"file_event"}
- PUA - Process Hacker Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - System Informer Execution · test · medium · {"category":"process_creation","product":"windows"}
- Potentially Suspicious Execution From Parent Process In Public Folder · test · high · {"category":"process_creation","product":"windows"}
- Virtualbox Driver Installation or Starting of VMs · test · low · {"category":"process_creation","product":"windows"}
- CrashControl CrashDump Disabled · test · medium · {"product":"windows","category":"registry_set"}
- Sysmon Configuration Error · test · high · {"product":"windows","category":"sysmon_error"}
- Sysmon Configuration Modification · test · high · {"product":"windows","category":"sysmon_status"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0502 Detection Strategy for Hidden Artifacts Across Platforms
AN1384 Analytic 1384
Abuse of file/registry attributes to hide malicious files, directories, or services. Defender view: detection of attrib.exe setting hidden/system flags, creation of Alternate Data Streams, or registry keys altering file visibility.
AN1385 Analytic 1385
Hidden file creation using leading '.' or file attribute changes with chattr (immutable/hidden flags). Defender view: detect execution of chattr, lsattr anomalies, and unusual hidden files appearing in system directories.
AN1386 Analytic 1386
Hidden files via 'chflags hidden' or Apple-specific attributes, LaunchAgents/LaunchDaemons placed in non-standard hidden directories. Defender view: detect command execution modifying file flags and unusual plist creation in hidden paths.
AN1387 Analytic 1387
Abuse of VMFS or ESXi shell to hide datastore files, renaming/moving VMDK or VMX files into hidden directories. Defender view: anomalous ESXi shell commands or file operations obscuring VM artifacts.
AN1388 Analytic 1388
Malicious macros or embedded objects hidden within Office documents by renaming streams or using hidden OLE objects. Defender view: detection of hidden macro streams or objects in documents correlated with anomalous execution.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.