Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1564.001

T1564.001Hidden Files and Directories

T1564.001 — Hidden Files and Directories is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 13 detection use cases covering it and 7 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
7Articles
0Sub-techniques
1Tactic

Use cases covering this technique (13)

Disable Show Hidden Files ESCU actions · hunting P MacOS Hidden Files and Directories ESCU actions · hunting P Reg exe used to hide files directories via registry keys ESCU actions · alerting P [LLM] PHP CLI drops hidden /tmp dropper artefacts (Laravel-Lang autoload payload) Bespoke install · alerting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] node.exe spawns detached child from tmpdir after npm install (moika.tech dropper) Bespoke install · hunting DSPDDCS [LLM] PowerShower dropped to user Pictures folder as googleearth.ps1 Bespoke install · alerting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDDCS [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] Linux Python RAT orphaned via nohup python3 /tmp/ld.py (Axios npm payload) Bespoke install · alerting DSΣPDDCS [LLM] macOS Axios RAT daemon spoof + ad-hoc codesign of hidden /private/tmp binary Bespoke install · alerting DSΣPDDCS

Articles citing this technique (7)