Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1564.003

T1564.003Hidden Window

T1564.003 — Hidden Window is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 6 detection use cases covering it and 4 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Headless Browser Mockbin or Mocky Request ESCU actions · alerting P Headless Browser Usage ESCU actions · hunting P Windows ConHost with Headless Argument ESCU actions · alerting P [LLM] supportdev.exe Inno Setup loader spawning hidden-window PowerShell Bespoke install · alerting DSΣPDDCS [LLM] Detached hidden node.exe executing sync.js from NodeJS masquerade path Bespoke install · alerting DSΣPDDCS [LLM] Four-way node.exe -e fanout spawned from VSCode shell descendants (BlokTrooper stage-2) Bespoke install · alerting DSPDDCS

Articles citing this technique (4)