Compliance Node Overview
MITRE ATT&CK T1027.014 (Polymorphic Code) is an Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection. Polymorphic code is a type of software capable of changing its runtime footprint during code execution. With each execution of the software, the code is mutated into a different version of itself that achieves the same purpose or objective as the original. This functionality enables the malware to evade traditional signature-based defenses, such as antivirus and antimalware tools. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1049 Antivirus/Antimalware. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, CM-02, CM-06, CM-07, SI-02, SI-03, SI-04, SI-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/014/
SHA-256 integrity: e778632cef47e4f1f8c72039e75ba4555342842be262414bfd5255a5bd615093
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1027.014: Polymorphic Code (https://attack.mitre.org/techniques/T1027/014/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access