Detecttechnique

D3-FCOAFile Content Analysis

File Content Analysis

Definition

Employing a pattern matching algorithm to statically analyze the content of files.

Defends against99

TypeTargetConfidenceTier
SubTechniqueAsymmetric Cryptographyt1573.002100%live
SubTechniqueSpearphishing Attachmentt1566.001100%live
SubTechniqueSystemd Servicet1543.002100%live
SubTechniqueTrapt1546.005100%live
SubTechnique/etc/passwd and /etc/shadowt1003.008100%live
SubTechniqueRename System Utilitiest1036.003100%live
SubTechniqueDylib Hijackingt1574.004100%live
SubTechniqueCompile After Deliveryt1027.004100%live
TechniqueAutomated Collectiont1119100%live
SubTechniqueMalicious Filet1204.002100%live
SubTechniqueThread Execution Hijackingt1055.003100%live
SubTechniqueSpearphishing via Servicet1566.003100%live
SubTechniquePluggable Authentication Modulest1556.003100%live
SubTechniqueMatch Legitimate Name or Locationt1036.005100%live
SubTechniqueEmondt1546.014100%live
SubTechniqueSpace after Filenamet1036.006100%live
SubTechniqueSoftware Packingt1027.002100%live
TechniqueSoftware Deployment Toolst1072100%live
SubTechniquePassword Filter DLLt1556.002100%live
SubTechniqueVBA Stompingt1564.007100%live
SubTechniqueLocal Data Stagingt1074.001100%live
SubTechniqueExfiltration Over Asymmetric Encrypted Non-C2 Protocolt1048.002100%live
TechniqueXSL Script Processingt1220100%live
TechniqueRemote System Discoveryt1018100%live
SubTechniqueOffice Template Macrost1137.001100%live
SubTechniqueImpair Command History Loggingt1562.003100%live
SubTechniqueHidden Userst1564.002100%live
SubTechniqueAppInit DLLst1546.010100%live
SubTechniqueMSBuildt1127.001100%live
SubTechniqueNetwork Logon Scriptt1037.003100%live

Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Defence
File Content Rules
Defence
File Access Pattern Analysis
Defence
Emulated File Analysis
Defence
File Content Decompression Checking
Defence
File Hashing
Defence
File Integrity Monitoring
Sourced from MITRE D3FEND ontology. Curated by Adam Lundqvist, SQUR.