What MITRE ATT&CK T1027: Obfuscated Files or Information (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1027 covers adversary use of obfuscation, encoding, encryption, and packing to evade detection. Sub-techniques include Binary Padding (T1027.001), Software Packing (T1027.002), Steganography (T1027.003), Compile After Delivery (T1027.004), Indicator Removal from Tools (T1027.005), HTML Smuggling (T1027.006), Dynamic API Resolution (T1027.007), and Stripped Payloads (T1027.008). Modern campaigns including APT41 (China), Lazarus (DPRK), and BianLian ransomware extensively use these techniques. Compliance obligations include behavioural detection (NIST 800-53 SI-3 with content-agnostic analysis), entropy-based anomaly detection, and detonation-based static analysis required under NIS2 Article 21.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1027/
SHA-256 integrity: 2f5dfcc5bfbdd295bba123c8d2daf0a4e03731a287b5106db20ab1fa5fdcab5c
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1027: Obfuscated Files or Information (https://attack.mitre.org/techniques/T1027/) with 8 sub-techniques
- NIST SP 800-53 Rev 5: SI-3 (Malicious Code Protection), SI-4 (Information System Monitoring)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access