Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1620: Reflective Code Loading (Enterprise Tactic TA0005 - Defense Evasion)

MITRE ATT&CK T1620 (Reflective Code Loading) is an Enterprise Defense Evasion technique. Adversaries may reflectively load code into a process in order to…

What MITRE ATT&CK T1620: Reflective Code Loading (Enterprise Tactic TA0005 - Defense Evasion) requires

MITRE ATT&CK T1620 (Reflective Code Loading) is an Enterprise Defense Evasion technique. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the memory of the process, vice creating a thread or process backed by a file path on disk (e.g., Shared Modules). Reflectively loaded payloads may be compiled binaries, anonymous files (only present in RAM), or just snubs of fileless executable code (ex: position-independent shellcode). Affected platforms: macOS, Linux, Windows.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1620/

SHA-256 integrity: 7f2dd7988d30b7b585e6e7bb07845bd0f749728070bee1084600278f77dc2dfe

Primary Citations — 5 traced to source

  • MITRE ATT&CK Technique T1620: Reflective Code Loading (https://attack.mitre.org/techniques/T1620/)
  • MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)

+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.