Detecttechnique

D3-EFAEmulated File Analysis

Emulated File Analysis

Definition

Emulating instructions in a file looking for specific patterns.

Defends against38

TypeTargetConfidenceTier
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueScreensavert1546.002100%live
SubTechniqueMshtat1218.005100%live
SubTechniqueLogin Hookt1037.002100%live
SubTechniqueRC Scriptst1037.004100%live
SubTechniquePath Interception by PATH Environment Variablet1574.007100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
SubTechniqueLocal Email Collectiont1114.001100%live
TechniqueDeobfuscate/Decode Files or Informationt1140100%live
SubTechniqueVBA Stompingt1564.007100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueOutlook Formst1137.003100%live
TechniqueXSL Script Processingt1220100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniqueCompile After Deliveryt1027.004100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniquePowerShell Profilet1546.013100%live
SubTechniqueTrapt1546.005100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueWeb Shellt1505.003100%live
SubTechniqueAccessibility Featurest1546.008100%live
SubTechniqueSpearphishing Linkt1566.002100%live
TechniqueInternal Spearphishingt1534100%live

Showing top 30 of 38 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Content Analysis
Defence
File Access Pattern Analysis
Defence
System File Analysis
Defence
Firmware Behavior Analysis
Defence
File Creation Analysis
Defence
Dynamic Analysis
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.