1200KM / simulation
T1027.013 Encrypted/Encoded File — Attack Simulation
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for…
Technique description
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Turla Snake Queue File Artifact
Procedure 6e8dea32-206e-482c-bdfa-f1ca6a737258; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Decode Eicar File and Write to File
Procedure 7693ccaa-8d64-4043-92a5-a2eb70359535; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Decrypt Eicar File and Write to File
Procedure b404caaa-12ce-43c7-9214-62a531c044f7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Password-Protected ZIP Payload Extraction and Execution
Procedure c2ca068a-eb1e-498f-9f93-3d554c455916; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- APT28 · G0007
- Darkhotel · G0012
- Putter Panda · G0024
- APT18 · G0026
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Group5 · G0043
- menuPass · G0045
- OilRig · G0049
- APT32 · G0050
- Magic Hound · G0059
- APT33 · G0064
- Leviathan · G0065
- Elderwood · G0066
- Dark Caracal · G0070
- APT19 · G0073
- Tropic Trooper · G0081
- APT39 · G0087
- TA505 · G0092
- Kimsuky · G0094
- APT-C-36 · G0099
- Inception · G0100
- Mofang · G0103
- Whitefly · G0107
- Blue Mockingbird · G0108
- Fox Kitten · G0117
- Sidewinder · G0121
- Higaisa · G0126
- Transparent Tribe · G0134
- TeamTNT · G0139
- BITTER · G1002
- Moses Staff · G1009
- Metador · G1013
- TA2541 · G1018
- Malteiro · G1026
- Saint Bear · G1031
- Moonstone Sleet · G1036
- Storm-1811 · G1046
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.