Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1140

T1140Deobfuscate/Decode Files or Information

T1140 — Deobfuscate/Decode Files or Information is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 15 detection use cases covering it and 16 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
16Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

[WEEKLY] Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Internal delivery · alerting DSΣP CertUtil With Decode Argument ESCU actions · alerting P Linux Auditd Base64 Decode Files ESCU actions · hunting P [LLM] BusySnake NSIS dropper: pnx.exe injected from Temp\ns*.tmp staging folder Bespoke install · alerting DSΣPDDCS [LLM] LoLBin abuse: certutil decode/urlcache, bitsadmin transfer, wmic process-call-create Bespoke install · hunting DSΣPDDCS [LLM] Bun spawned from npm install context executing /tmp/p*.js implant Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] node process spawning bash/curl chain to fetch Velora DEX install.sh dropper Bespoke delivery · alerting DSΣPDDCS [LLM] Python spawning python -c with base64.b64decode exec (litellm .pth stage-1 launcher) Bespoke install · alerting DSΣP [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) Bespoke exploit · hunting DSPDDCS [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] XZ Utils (CVE-2024-3094) build-time backdoor extraction from disguised test corpus Bespoke install · alerting DSΣPDDCS [LLM] Non-browser process reading Chrome/Edge/Opera Login Data or Local State Bespoke actions · alerting DSΣPDDCS [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] gxm-reference encrypted-payload artifacts written to disk (obfusc/mac/win/lin .enc.js) Bespoke delivery · alerting DSΣPDDCS

Articles citing this technique (16)