1200KM / simulation
T1027 Obfuscated Files or Information — Attack Simulation
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection.…
Technique description
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- DLP Evasion via Sensitive Data in VBA Macro over email
Procedure 129edb75-d7b8-42cd-a8ba-1f3db64ec4ad; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execute base64-encoded PowerShell from Windows Registry
Procedure 450e7218-7915-4be4-8b9b-464a49eafcec; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Obfuscated PowerShell Command via Character Array
Procedure 6683baf0-6e77-4f58-b114-814184ea8150; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Snake Malware Encrypted crmlog file
Procedure 7e47ee60-9dd1-4269-9c4f-97953b183268; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Obfuscated Command in PowerShell
Procedure 8b3f4ed6-077b-4bdd-891c-2d237f19410f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execute base64-encoded PowerShell
Procedure a50d5a97-2531-499e-a1de-5544c74432c6; elevation not declared required; cleanup not declared. Not executed or individually validated.
- DLP Evasion via Sensitive Data in VBA Macro over HTTP
Procedure e2d85e66-cb66-4ed7-93b1-833fc56c9319; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Obfuscated Command Line using special Unicode characters
Procedure e68b945c-52d0-4dd9-a5e8-d173d70c448f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Decode base64 Data into Script
Procedure f45df6be-2e1e-4136-a384-8f18ab3826fb; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Execution from Compressed File
Procedure f8c8a909-5f29-49ac-9244-413936ce6d1f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Execution from Compressed JScript File
Procedure fad04df1-5229-4185-b016-fb6010cd87ac; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT3 · G0022
- Sandworm Team · G0034
- Gamaredon Group · G0047
- BlackOasis · G0063
- APT37 · G0067
- Gallmaker · G0084
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- APT-C-36 · G0099
- Rocke · G0106
- Windshift · G0112
- Mustang Panda · G0129
- BackdoorDiplomacy · G0135
- Earth Lusca · G1006
- Moonstone Sleet · G1036
- RedCurl · G1039
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.