Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1620

T1620Reflective Code Loading

T1620 — Reflective Code Loading is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 10 detection use cases covering it and 9 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
9Articles
0Sub-techniques
1Tactic

Use cases covering this technique (10)

PowerShell PInvoke Process Injection API Chain ESCU actions · alerting P Windows MMC Loaded Script Engine DLL ESCU actions · hunting P [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) Bespoke exploit · alerting DSΣPDDCS [LLM] MIXEDKEY encrypted payload: .PCPKEY file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] msaRAT msiexec executing update_ms.msi (fake Windows update custom action) Bespoke install · alerting DSΣPDDCS [LLM] In-memory WLDR PowerShell C2 implant (fileless, no -File, unusual parent) Bespoke c2 · hunting DSPDDCS [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS [LLM] Bun spawned from npm install context executing /tmp/p*.js implant Bespoke install · alerting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS

Articles citing this technique (9)