Hide Artifacts T1564

Tactic: Stealth

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.

Events covered

30 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 4Sysmon service state changed
SysmonEvent ID 5Process terminated
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
SysmonEvent ID 16ServiceConfigurationChange
SysmonEvent ID 255Error report: UtcTime: UtcTime ID: ID Description: Description.
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4657A registry value was modified.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 5136A directory service object was modified.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Defender-DeviceFileEventsanyFile activity
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFcreateFile or Directory Create
ESFrenameFile Rename
ESFwriteFile Write
Linux-AuditdEvent ID 1309EXECVE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
ServicingEvent ID 9Selectable update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier was successfully turned on.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 173 rules share fields, values, and exclusions.

Fields filtered most (107 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine62contains 44, regex_match 17, wildcard 4, eq 1, in 1, is_not_null 1--headless, (?i)\.cab|(-|\/)F:|\x5cAppData\x5c|(Local|Roaming)\x5cTemp\x5c, (?i)(\s+ADD\s+.*\/d.*0), (?i)(esentutl|\.exe)"?\s.*\/y\s.*\/d\s, (?i)-w(indowStyle)?\s+hidden
event.type55eq 51, in 3, ne 1start, creation, change, process_started, deletion
process_name54eq 25, in 15, starts_with 10, wildcard 3, regex_match 2., bash, cp, csh, dash
EventType46eq 33, in 13, ne 1exec, exec_event, connection_attempted, executed, modification
Image42ends_with 29, starts_with 7, contains 5, eq 2, is_not_null 2, wildcard 2, in 1, regex_match 1/dev/shm/, ./, /boot/, \attrib.exe, /media/
host.os.type32eq 31, in 1
process.args28eq 12, wildcard 8, in 7, starts_with 5, contains 3, ends_with 2, regex_match 1-o, -c, &, --options, /*/.*
EventID19eq 194688, 1, 15, 4103, 4104
TargetFilename19contains 6, starts_with 5, ends_with 3, regex_match 3, wildcard 3, eq 1(?<!\/)\b\w+(\.\w+)?:\w+(\.\w+)?$, .bat:zone, .cmd:zone, .dll:zone, .bat.exe
OriginalFileName18eq 18, in 1attrib.exe, sc.exe, findstr.exe, advancedrun.exe, cmd.exe
ParentImage15ends_with 6, is_not_null 6, eq 3, starts_with 3, contains 2\thor\thor64.exe, \webex\webexhost.exe, /boot/, /dev/shm/, /opt/.
event.category11eq 10, in 1process, file, authentication, registry
parent_process_name10starts_with 3, eq 2, regex_match 2, in 1, ne 1, wildcard 1., ^C:\x5cUsers\x5cPublic, bash, launchd, osascript
Details9eq 8, is_not_null 1, length_compare 1dword (0x00000000), 0, 1, 0x00000000, 0x00000001
TargetObject8contains 4, ends_with 4, wildcard 2\(default), \control\safeboot\minimal\, \control\safeboot\minimal\hexnode agent\(default), \enablescripts, \microsoft\powershellcore\

Top indicator values (1372 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
441087
event.typeeq
creation
752
EventTypeeq
exec
28579
process_namestarts_with
.
938
EventTypein
exec
7206
EventTypein
exec_event
7150
EventTypein
start
7168
event.categoryeq
process
7141
CommandLinecontains
--headless
68
EventIDeq
4688
6317
EventIDeq
1
5242
Imagestarts_with
/dev/shm/
553
Imagestarts_with
/tmp/
558
Imagestarts_with
/var/tmp/
556
Imagestarts_with
./
426
Imagestarts_with
/boot/
428
process_namein
bash
5202
process_namein
csh
5159
process_namein
fish
5163
process_namein
ksh
5163
process_namein
sh
5197
process_namein
tcsh
5156
process_namein
zsh
5196
process_namein
dash
4170
Detailseq
dword (0x00000000)
438
OriginalFileNameeq
attrib.exe
45
ParentImageends_with
\thor\thor64.exe
4
ParentImageends_with
\webex\webexhost.exe
4
file.namestarts_with
.
47
process_nameeq
mount
49

Exclusions (670 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
ParentCommandLineeq
runc init
8
Imagestarts_with
/tmp/newroot/
4
ParentImageends_with
\thor\thor64.exe
4
ParentImageends_with
\webex\webexhost.exe
4
dest_ipcidr_match
10.0.0.0/8
4
dest_ipcidr_match
100.64.0.0/10
4
dest_ipcidr_match
127.0.0.0/8
4
dest_ipcidr_match
169.254.0.0/16
4
dest_ipcidr_match
172.16.0.0/12
4
dest_ipcidr_match
192.0.0.0/24
4
dest_ipcidr_match
192.0.2.0/24
4
dest_ipcidr_match
192.168.0.0/16
4
dest_ipcidr_match
192.175.48.0/24
4
dest_ipcidr_match
192.31.196.0/24
4
dest_ipcidr_match
192.52.193.0/24
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 65 rules

Elastic 68 rules

Splunk 31 rules

Kusto 6 rules

YARA-L 1 rule

Panther 2 rules