1200KM / simulation
T1027.004 Compile After Delivery — Attack Simulation
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW. Source code payloads may also be encrypted, encoded, and/or embedded within…
Technique description
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code files may subvert analysis and scrutiny from protections targeting executables/binaries. These payloads will need to be compiled before execution; typically via native utilities such as ilasm.exe, csc.exe, or GCC/MinGW. Source code payloads may also be encrypted, encoded, and/or embedded within…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Dynamic C# Compile
Procedure 453614d8-3ba6-4147-acc0-7ec4b3e1faef; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Go compile
Procedure 78bd3fa7-773c-449e-a978-dc1f1500bc52; elevation not declared required; cleanup not declared. Not executed or individually validated.
- C compile
Procedure d0377aa6-850a-42b2-95f0-de558d80be57; elevation not declared required; cleanup not declared. Not executed or individually validated.
- CC compile
Procedure da97bb11-d6d0-4fc1-b445-e443d1346efe; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Compile After Delivery using csc.exe
Procedure ffcdbd6a-b0e8-487d-927a-09127fe9a206; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.