Compliance Node Overview
MITRE ATT&CK T1027.002 (Software Packing) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. Affected platforms: macOS, Windows, Linux. MITRE-documented mitigations include M1049 Antivirus/Antimalware. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/002/
SHA-256 integrity: 12212626a70d927ed72618ed2178ce6065221b0a0012cf44091706d2f95cd4ee
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1027.002: Software Packing (https://attack.mitre.org/techniques/T1027/002/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.