{"id":"T1564.012","name":"File/Path Exclusions","url":"https://attack.mitre.org/techniques/T1564/012","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0051","stix_id":"x-mitre-detection-strategy--f9175415-59ba-497c-b96f-639e01f4cf4e","name":"Detection Strategy for File/Path Exclusions","url":"https://attack.mitre.org/detectionstrategies/DET0051","analytics":[{"id":"AN0139","stix_id":"x-mitre-analytic--620cae28-1874-462d-a2e4-47ddd75098ea","name":"Analytic 0139","description":"Creation or modification of files in directories known to be excluded from AV scanning (e.g., C:\\Windows\\Temp, Exchange server directories, or default AV exclusions). Defender perspective: correlate file creation with execution behavior or anomalous parent processes writing to excluded paths.","url":"https://attack.mitre.org/detectionstrategies/DET0051#AN0139","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Security","channel":"EventCode=4663, 4670, 4656","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"ExcludedPaths","description":"List of directories excluded from scanning in the environment (customizable per organization)."},{"field":"ProcessAllowlist","description":"Legitimate processes typically writing to excluded paths to minimize false positives."}],"live":true,"detection_strategies":["DET0051"],"techniques":["T1564.012"]},{"id":"AN0140","stix_id":"x-mitre-analytic--fd7bf05d-6f80-471c-99bf-7aa82ab25440","name":"Analytic 0140","description":"Adversaries writing or moving payloads into directories configured as AV/EDR exclusion paths (e.g., /tmp, /var/lib, or custom directories from auditd exclusion rules). Defender perspective: detect file creation in paths matching known exclusions correlated with unusual parent processes.","url":"https://attack.mitre.org/detectionstrategies/DET0051#AN0140","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open or creat syscalls targeting excluded paths","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:PATH","channel":"file path matches exclusion directories","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"auditd-path"}],"mutable_elements":[{"field":"ExcludedDirectories","description":"System- or security-tool-configured exclusion directories where files should rarely change."},{"field":"CorrelationWindow","description":"Time window to correlate file creation in excluded paths with execution or network activity."}],"live":true,"detection_strategies":["DET0051"],"techniques":["T1564.012"]},{"id":"AN0141","stix_id":"x-mitre-analytic--3643a313-1aa7-44d1-b3e2-e97ad65c6837","name":"Analytic 0141","description":"Suspicious file creation or modification in directories ignored by XProtect or AV exclusions (e.g., ~/Library, temporary cache directories). Defender perspective: monitor file events in ignored paths with correlation to execution or persistence activity.","url":"https://attack.mitre.org/detectionstrategies/DET0051#AN0141","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"file creation in AV exclusion directories","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"process writes or modifies files in excluded paths","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AVExclusionPaths","description":"Paths ignored by AV/XProtect that should be monitored for abnormal writes."},{"field":"ProcessContext","description":"Expected user or application context writing to excluded directories."}],"live":true,"detection_strategies":["DET0051"],"techniques":["T1564.012"]}],"live":true,"version":"1.0","techniques":["T1564.012"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}