What MITRE ATT&CK T1620: Reflective Code Loading (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1620 (Reflective Code Loading) is an Enterprise Defense Evasion technique. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). Affected platforms: macOS, Linux, Windows.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1620/
SHA-256 integrity: 7f2dd7988d30b7b585e6e7bb07845bd0f749728070bee1084600278f77dc2dfe
Primary Citations — 5 traced to source
- MITRE ATT&CK Technique T1620: Reflective Code Loading (https://attack.mitre.org/techniques/T1620/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1620-reflective-code-loading.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1620-reflective-code-loading.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1620-reflective-code-loading
- Back to registry: Browse all 10,085 compliance nodes