Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1678: Delay Execution (Enterprise Tactic TA0005 - Stealth)

MITRE ATT&CK T1678 (Delay Execution) is an Enterprise Stealth technique. Adversaries may employ various time-based methods to evade detection and…

What MITRE ATT&CK T1678: Delay Execution (Enterprise Tactic TA0005 - Stealth) requires

MITRE ATT&CK T1678 (Delay Execution) is an Enterprise Stealth technique. Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with benign activity, and avoid scrutiny. Adversaries can perform this behavior within virtualization/sandbox environments or natively on host systems. Adversaries may utilize programmatic `sleep` commands or native system scheduling functionality, for example Scheduled Task/Job. Benign commands or other operations may also be used to delay malware execution or ensure prior commands have had time to execute properly. Loops or otherwise needless repetitions of commands, such as `ping`, may be used to delay malware execution and potentially exceed time thresholds of automated analysis environments... Affected platforms: Linux, macOS, Windows.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1678/

SHA-256 integrity: 7ce155466d14113f8fa2b0f4ef06860d1cb1e9a05e716eb906d17fd5d6d86790

Primary Citations — 4 traced to source

  • MITRE ATT&CK Technique T1678: Delay Execution (https://attack.mitre.org/techniques/T1678/)
  • MITRE ATT&CK Tactic TA0005: Stealth (https://attack.mitre.org/tactics/TA0005/)

+ 2 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.