Isolatesubtechnique

D3-FCDCFile Content Decompression Checking

Definition

Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge

Defends against99

TypeTargetConfidenceTier
SubTechniqueCredentials In Filest1552.001100%live
TechniqueArchive Collected Datat1560100%live
TechniqueCommand and Scripting Interpretert1059100%live
SubTechniqueRegistry Run Keys / Startup Foldert1547.001100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniquePath Interception by Search Order Hijackingt1574.008100%live
SubTechniqueAsymmetric Cryptographyt1573.002100%live
SubTechniqueLC_LOAD_DYLIB Additiont1546.006100%live
SubTechniqueArchive via Utilityt1560.001100%live
SubTechniqueWeb Protocolst1071.001100%live
SubTechniqueBinary Paddingt1027.001100%live
SubTechniqueCOR_PROFILERt1574.012100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
SubTechniqueLogin Hookt1037.002100%live
TechniqueFile and Directory Discoveryt1083100%live
SubTechniqueClear Linux or Mac System Logst1070.002100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueLaunchdt1053.004100%live
SubTechniqueDynamic-link Library Injectiont1055.001100%live
TechniqueSoftware Deployment Toolst1072100%live
SubTechniquePluggable Authentication Modulest1556.003100%live
SubTechniquePath Interception by Unquoted Patht1574.009100%live
SubTechniqueEmondt1546.014100%live
SubTechniqueArchive via Custom Methodt1560.003100%live
SubTechniqueFile Deletiont1070.004100%live
SubTechniqueTrapt1546.005100%live
SubTechniqueVDSO Hijackingt1055.014100%live
TechniqueSystem Network Configuration Discoveryt1016100%live
SubTechniqueComponent Object Model Hijackingt1546.015100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Content Analysis
Defence
File Content Rules
Defence
File Format Verification
Defence
File Metadata Consistency Validation
Defence
File Hashing
Defence
File Carving
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.