Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1564.001

T1564.001Hidden Files and Directories

T1564.001 — Hidden Files and Directories is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 16 detection use cases covering it and 10 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
10Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

Disable Show Hidden Files ESCU actions · hunting P MacOS Hidden Files and Directories ESCU actions · hunting P Reg exe used to hide files directories via registry keys ESCU actions · alerting P [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc Bespoke install · alerting DSΣPCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] TuxBot/Akiru known ELF sample execution and drop (SHA256 pivot) Bespoke install · hunting DSΣPCS [LLM] IronWorm preinstall loader: detached hidden binary executed from OS temp by node.exe Bespoke install · alerting DSΣPDDCS [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) Bespoke install · alerting DSΣPDDCS [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary Bespoke install · alerting DSΣPDDCS [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (10)