What MITRE ATT&CK T1027.015: Compression (Enterprise Tactic TA0005 - Stealth) requires
MITRE ATT&CK T1027.015 (Compression) is an Enterprise Stealth technique. Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive multiple files together to make it easier and faster to transfer files. In addition to compressing files, adversaries may also compress shellcode directly - for example, in order to store it in a Windows Registry key (i.e., Fileless Storage). In order to further evade detection, adversaries may combine multiple ZIP files into one archive. This process of concatenation creates an archive that appears to be a single archive but in fact contains the central directories of the embedded archives. Some ZIP readers, such as 7zip, may not be able to identify concatenated ZIP files and miss the presence of the malicious payload. File archives may be s... Affected platforms: Linux, macOS, Windows. Sub-technique of ATT&CK T1027. ATT&CK-mapped mitigations: M1049 Antivirus/Antimalware.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/015/
SHA-256 integrity: d7d6990d9943334be28bd157ea94678e3a394961537297e5efb1e9d09651e225
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1027.015: Compression (https://attack.mitre.org/techniques/T1027/015/)
- MITRE ATT&CK Tactic TA0005: Stealth (https://attack.mitre.org/tactics/TA0005/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access