1200KM / simulation
T1553.005 Mark-of-the-Web Bypass — Attack Simulation
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in…
Technique description
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Mount ISO image
Procedure 002cca30-4778-4891-878a-aaffcfa502fa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Mount an ISO image and run executable from the ISO
Procedure 42f22b00-0242-4afc-a61b-0da05041f9cc; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Remove the Zone.Identifier alternate data stream
Procedure 64b12afc-18b8-4d3f-9eab-7f6cae7c73f9; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Execute LNK file from ISO
Procedure c2587b8d-743d-4985-aa50-c83394eaeb68; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.