Isolatesubtechnique
D3-FMBVFile Magic Byte Verification
Definition
Utilizing the magic number to verify the file
Defends against99
| Type | Target | Confidence | Tier |
|---|---|---|---|
| SubTechnique | RC Scriptst1037.004 | 100% | live |
| SubTechnique | Compile After Deliveryt1027.004 | 100% | live |
| SubTechnique | Archive via Utilityt1560.001 | 100% | live |
| SubTechnique | Screensavert1546.002 | 100% | live |
| SubTechnique | Clear Linux or Mac System Logst1070.002 | 100% | live |
| SubTechnique | AppInit DLLst1546.010 | 100% | live |
| SubTechnique | Local Email Collectiont1114.001 | 100% | live |
| SubTechnique | Hidden Userst1564.002 | 100% | live |
| Technique | Exfiltration Over C2 Channelt1041 | 100% | live |
| SubTechnique | Accessibility Featurest1546.008 | 100% | live |
| SubTechnique | Credentials from Web Browserst1555.003 | 100% | live |
| SubTechnique | Network Logon Scriptt1037.003 | 100% | live |
| SubTechnique | Hidden Windowt1564.003 | 100% | live |
| Technique | Rootkitt1014 | 100% | live |
| SubTechnique | Sudo and Sudo Cachingt1548.003 | 100% | live |
| SubTechnique | Login Hookt1037.002 | 100% | live |
| Technique | System Network Configuration Discoveryt1016 | 100% | live |
| Technique | Archive Collected Datat1560 | 100% | live |
| SubTechnique | Rundll32t1218.011 | 100% | live |
| Technique | Forced Authenticationt1187 | 100% | live |
| SubTechnique | Dylib Hijackingt1574.004 | 100% | live |
| SubTechnique | Impair Command History Loggingt1562.003 | 100% | live |
| SubTechnique | Path Interception by Unquoted Patht1574.009 | 100% | live |
| SubTechnique | Bash Historyt1552.003 | 100% | live |
| SubTechnique | VDSO Hijackingt1055.014 | 100% | live |
| SubTechnique | Proc Memoryt1055.009 | 100% | live |
| SubTechnique | Emondt1546.014 | 100% | live |
| SubTechnique | Plist Modificationt1547.011 | 100% | live |
| SubTechnique | Outlook Formst1137.003 | 100% | live |
| SubTechnique | Binary Paddingt1027.001 | 100% | live |
Showing top 30 of 99 by confidence. Click any target to see the full neighbourhood.
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.