1200KM / simulation
T1564.001 Hidden Files and Directories — Attack Simulation
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface…
Technique description
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Hidden files
Procedure 3b7015f2-3144-4205-b799-b05580621379; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Create a hidden file in a hidden directory
Procedure 61a782e5-9a19-40b5-8ba4-69a4b9f3d7be; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create Windows Hidden File with powershell
Procedure 7f66d539-4fbe-4cfa-9a56-4a2bf660c58a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Show all hidden files
Procedure 9a1ec7da-b892-449f-ad68-67066d04380c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Hide a Directory
Procedure b115ecaf-3b24-4ed2-aefe-2fcb9db913d3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Mac Hidden file
Procedure cddb9098-3b47-4e01-9d3b-6f5f323288a9; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Create Windows System File with powershell
Procedure d380c318-0b34-45cb-9dad-828c11891e43; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Windows Hidden File with Attrib
Procedure dadb792e-4358-4d8d-9207-b771faa0daa5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Hide Files Through Registry
Procedure f650456b-bd49-4bc1-ae9d-271b5b9581e7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Windows System File with Attrib
Procedure f70974c8-c094-4574-b542-2c545af95a32; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.