What MITRE ATT&CK T1678: Delay Execution (Enterprise Tactic TA0005 - Stealth) requires
MITRE ATT&CK T1678 (Delay Execution) is an Enterprise Stealth technique. Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with benign activity, and avoid scrutiny. Adversaries can perform this behavior within virtualization/sandbox environments or natively on host systems. Adversaries may utilize programmatic `sleep` commands or native system scheduling functionality, for example Scheduled Task/Job. Benign commands or other operations may also be used to delay malware execution or ensure prior commands have had time to execute properly. Loops or otherwise needless repetitions of commands, such as `ping`, may be used to delay malware execution and potentially exceed time thresholds of automated analysis environments... Affected platforms: Linux, macOS, Windows.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1678/
SHA-256 integrity: 7ce155466d14113f8fa2b0f4ef06860d1cb1e9a05e716eb906d17fd5d6d86790
Primary Citations — 4 traced to source
- MITRE ATT&CK Technique T1678: Delay Execution (https://attack.mitre.org/techniques/T1678/)
- MITRE ATT&CK Tactic TA0005: Stealth (https://attack.mitre.org/tactics/TA0005/)
+ 2 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1678-delay-execution.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1678-delay-execution.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1678-delay-execution
- Back to registry: Browse all 10,085 compliance nodes