{"id":"T1564.005","name":"Hidden File System","url":"https://attack.mitre.org/techniques/T1564/005","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0461","stix_id":"x-mitre-detection-strategy--82c31276-f916-4d67-be83-f09534c0c77e","name":"Detection Strategy for Hidden File System Abuse","url":"https://attack.mitre.org/detectionstrategies/DET0461","analytics":[{"id":"AN1271","stix_id":"x-mitre-analytic--8d7fb300-189d-4654-ba66-3612a8a4cf65","name":"Analytic 1271","description":"Anomalous creation or mounting of hidden partitions or virtual file systems. Defender view: detection of registry modifications linked to non-standard file systems, suspicious disk I/O patterns, or bootkit-like behavior where hidden volumes are accessed outside normal file system APIs.","url":"https://attack.mitre.org/detectionstrategies/DET0461#AN1271","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"etw:Microsoft-Windows-Kernel-Storage","channel":"Raw disk I/O operations bypassing NTFS APIs","data_component":"DC0004","data_component_name":"Firmware Modification","log_source_slug":"etw-microsoft-windows-kernel-storage"}],"mutable_elements":[{"field":"MonitoredRegistryKeys","description":"Specify registry paths for mount points and hidden partition configs."},{"field":"DiskIOThreshold","description":"Tune thresholds for raw disk access outside expected drivers."},{"field":"TimeWindow","description":"Correlate boot-time anomalies with hidden file system mounting activity."}],"live":true,"detection_strategies":["DET0461"],"techniques":["T1564.005"]},{"id":"AN1272","stix_id":"x-mitre-analytic--35300a0c-e135-4865-9fe5-9d65a1c77dda","name":"Analytic 1272","description":"Unusual mounting of loopback or pseudo file systems not aligned with legitimate administrative activity. Defender view: monitoring auditd and syslog for mount commands involving suspicious mount points, reserved blocks, or device mappings indicative of hidden partitions.","url":"https://attack.mitre.org/detectionstrategies/DET0461#AN1272","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"mount or losetup commands creating hidden or encrypted FS","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Sudo or root escalation followed by filesystem mount commands","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"AllowedMountPoints","description":"Whitelist standard mount points to reduce false positives."},{"field":"UserContext","description":"Flag root escalation during mount operations."}],"live":true,"detection_strategies":["DET0461"],"techniques":["T1564.005"]},{"id":"AN1273","stix_id":"x-mitre-analytic--82908b5f-fa84-4420-bb1c-cc77e12e9d3c","name":"Analytic 1273","description":"Hidden file system use through APFS containers or custom plist configuration. Defender view: anomalous use of hdiutil or diskutil to attach hidden partitions, modification of plist entries tied to system volumes, or suspicious raw disk access.","url":"https://attack.mitre.org/detectionstrategies/DET0461#AN1273","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Execution of diskutil or hdiutil attaching hidden partitions","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Hidden volume attachment or modification events","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"MonitoredPlistPaths","description":"Adjust to target only relevant plist files linked to volume mounting."},{"field":"ProcessScope","description":"Restrict monitoring to sensitive processes like diskutil and hdiutil."}],"live":true,"detection_strategies":["DET0461"],"techniques":["T1564.005"]}],"live":true,"version":"1.0","techniques":["T1564.005"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}