1200KM / simulation
T1564 Hide Artifacts — Attack Simulation
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system…
Technique description
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Command Execution with NirCmd
Procedure 2748ab4a-1e0b-4cf2-a2b0-8ef765bec7be; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create a Hidden User Called "$"
Procedure 2ec63cc2-4975-41a6-bf09-dffdfb610778; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create and Hide a Service with sc.exe
Procedure 333c7de0-6fbe-42aa-ac2b-c7e40b18246a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create an "Administrator " user (with a space on the end)
Procedure 5bb20389-39a5-4e99-9264-aeb92a55a85c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Extract binary files via VBA
Procedure 6afe288a-8a8b-4d33-a629-8d03ba9dad3a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.