kevmap

TechniquesT1564 › T1564.001

T1564.001 Hidden Files and Directories

stealth — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
9
Sigma rules tagged attack.t1564.001
0
KEV CVEs mapped here
<p>Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (<code>dir /a</code> for Windows and <code>ls –a</code> for Linux and macOS).</p><p>On Linux and Mac, users can mark specific files as hidden simply by putting a “.” as the first character in the file or folder name. Files and folders that start with a period, ‘.’, are by default hidden from being viewed in the Finder application and standard command-line utilities like “ls”. Users must specifically change settings to have these files viewable.</p><p>Files on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app. On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn’t clutter up the user’s workspace. For example, SSH utilities create a .ssh folder that’s hidden and contains the user’s known hosts and keys.</p><p>Additionally, adversaries may name files in a manner that would allow the file to be hidden such as naming a file only a “space” character.</p><p>Adversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1564.001

Author: frack113 · 2022-04-04 (modified 2025-10-22) · logsource: product=windows category=registry_set · 1547e27c-3974-43e2-a7d7-7f484fb928ec
Detects the modification of the registry to allow a driver or service to persist in Safe Mode.
Techniques: T1564.001
Author: Sami Ruohonen · 2019-01-16 (modified 2023-03-14) · logsource: product=windows category=process_creation · 4281cb20-2994-4580-aa63-c8b86d019934
Detects usage of attrib.exe to hide files from users.
Techniques: T1564.001
Author: frack113 · 2022-07-18 (modified 2024-04-29) · logsource: product=windows category=process_creation · 4ae81040-fc1c-4249-bfa3-938d260214d9
Detect use of icacls to deny access for everyone in Users folder sometimes used to hide malicious files
Techniques: T1564.001
Author: frack113 · 2022-04-02 (modified 2024-03-26) · logsource: product=windows category=registry_set · 5a5152f1-463f-436b-b2f5-8eceb3964b42
Detects modifications to the "Hidden" and "ShowSuperHidden" explorer registry values in order to disable showing of hidden files and system files. This technique is abused by several malware families to hide their files from normal users.
Techniques: T1564.001
Author: frack113 · 2022-02-04 (modified 2023-03-14) · logsource: product=windows category=process_creation · bb19e94c-59ae-4c15-8c12-c563d23fe52b
Detects the execution of "attrib" with the "+s" flag to mark files as system files
Techniques: T1564.001
Author: Pawel Mazur · 2021-09-06 (modified 2025-06-16) · logsource: product=linux service=auditd · d08722cd-3d09-449a-80b4-83ea2d9d4616
Detects adversary creating hidden file or directory, by detecting directories or files with . as the first character
Techniques: T1564.001
Author: Jason Phang Vern - Onn, Robbin Ooi Zhen Heng (Gen Digital) · 2025-11-22 · logsource: product=macos category=file_event · e710a880-1f18-4417-b6a0-b5afdf7e3023
Detects creation of persistence artifacts placed by Atomic MacOS Stealer in macOS systems. Recent Atomic MacOS Stealer variants have been observed dropping these to maintain persistent access after compromise.
Techniques: T1564.001T1543.004
Author: Nasreddine Bencherchali (Nextron Systems) · 2022-06-28 (modified 2023-03-14) · logsource: product=windows category=process_creation · efec536f-72e8-4656-8960-5e85d091345b
Detects the usage of attrib with the "+s" option to set scripts or executables located in suspicious locations as system files to hide them from users and make them unable to be deleted with simple rights. The rule limits the search to specific extensions and directories to avoid FPs
Techniques: T1564.001
Author: frack113 · 2022-04-02 (modified 2023-08-17) · logsource: product=windows category=registry_set · fecfd1a1-cc78-4313-a1ea-2ee2e8ec27a7
Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
Techniques: T1564.001T1112

Rules tagged at the parent level (attack.t1564) 10

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: frack113 · 2021-06-04 (modified 2022-08-02) · logsource: product=windows category=sysmon_status · 1f2b5353-573f-4880-8e33-7d04dcf97744
Detects when an attacker tries to hide from Sysmon by disabling or stopping it
Techniques: T1564
Author: Tobias Michalski (Nextron Systems) · 2022-02-24 (modified 2023-08-17) · logsource: product=windows category=registry_set · 2ff692c2-4594-41ec-8fcb-46587de769e0
Detects disabling the CrashDump per registry (as used by HermeticWiper)
Techniques: T1564T1112
Author: Florian Roth (Nextron Systems) · 2023-05-08 (modified 2024-11-23) · logsource: product=windows category=process_creation · 5722dff1-4bdd-4949-86ab-fbaf707e767a
Detects the execution of System Informer, a task manager tool to view and manipulate processes, kernel options and other low level operations
Techniques: T1082T1564T1543
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) · 2022-02-25 (modified 2024-07-12) · logsource: product=windows category=process_creation · 69bd9b97-2be2-41b6-9816-fb08757a4d1a
Detects a potentially suspicious execution of a parent process located in the "\Users\Public" folder executing a child process containing references to shell or scripting binaries and commandlines.
Techniques: T1564T1059
Author: frack113 · 2022-09-05 (modified 2023-12-11) · logsource: product=windows category=file_event · 74babdd6-a758-4549-9632-26535279e654
Detect creation of suspicious executable file names. Some strings look for suspicious file extensions, others look for filenames that exploit unquoted service paths.
Techniques: T1564
Author: Florian Roth (Nextron Systems) · 2022-10-10 (modified 2024-11-23) · logsource: product=windows category=process_creation · 811e0002-b13b-4a15-9d00-a613fce66e42
Detects the execution of Process Hacker based on binary metadata information (Image, Hash, Imphash, etc). Process Hacker is a tool to view and manipulate processes, kernel options and other low level options. Threat actors abused older vulnerable versions to manipulate system processes.
Techniques: T1622T1564T1543
Author: frack113 · 2021-06-04 (modified 2026-07-23) · logsource: product=windows category=sysmon_error · 815cd91b-7dbc-4247-841a-d7dd1392b0a8
Detects when an adversary is trying to hide it's action from Sysmon logging based on error messages
Techniques: T1564
Author: Janantha Marasinghe · 2020-09-26 (modified 2025-07-29) · logsource: product=windows category=process_creation · bab049ca-7471-4828-9024-38279a4c04da
Adversaries can carry out malicious operations using a virtual instance to avoid detection. This rule is built to detect the registration of the Virtualbox driver or start of a Virtualbox VM.
Techniques: T1564.006T1564
Author: frack113 · 2022-01-21 (modified 2023-01-05) · logsource: product=windows category=file_event · e15b518d-b4ce-4410-a9cd-501f23ce4a18
Once executed, colorcpl.exe will copy the arbitrary file to c:\windows\system32\spool\drivers\color\
Techniques: T1564
Author: Joseliyo Sanchez, @Joseliyo_Jstnk · 2023-01-12 · logsource: product=linux category=process_creation · ec52985a-d024-41e3-8ff6-14169039a0b3
Detects execution of the "mount" command with "hidepid" parameter to make invisible processes to other users from the system
Techniques: T1564