1200KM / simulation
T1001.002 Steganography — Attack Simulation
Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and…
Technique description
Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be used to hide data in digital messages that are transferred between systems. This hidden information can be used for command and control of compromised systems. In some cases, the passing of files embedded using steganography, such as image or document files, can be used for command and…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Embedded Script in Image Execution via Extract-Invoke-PSImage
Procedure 04bb8e3d-1670-46ab-a3f1-5cee64da29b6; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Execute Embedded Script in Image via Steganography
Procedure 4ff61684-ad91-405c-9fbc-048354ff1d07; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Steganographic Tarball Embedding
Procedure c7921449-8b62-4c4d-8a83-d9281ac0190b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.