T1564: Hide Artifacts
Adversaries may attempt to hide artifacts and malicious actions associated with behaviors to avoid detection by users and security tools.
Living-off-the-Land Matrix for T1564
Across 21 verified binariesDeviceCredentialDeployment.exe
Device Credential Deployment
DeviceCredentialDeploymentDiantz.exe
Binary that package existing files into a cabinet (.cab) file
Esentutl.exe
Binary for working with Microsoft Joint Engine Technology (JET) database
Expand.exe
Binary that expands one or more compressed files
Extrac32.exe
Extract to ADS, copy or overwrite a file with Extrac32.exe
Findstr.exe
Write to ADS, discover, or download files with Findstr.exe
Forfiles.exe
Selects and executes a command on a file or set of files. This command is useful for batch processing.
Makecab.exe
Binary to package existing files into a cabinet (.cab) file
MpCmdRun.exe
Binary part of Windows Defender. Used to manage settings in Windows Defender
msxsl.exe
Command line utility used to perform XSL transformations.
msxsl.exe {PATH:.xml} {PATH:.xsl}wsb.exe
Windows Sandbox command-line interface. Creates, lists, controls, and executes commands inside Windows Sandbox sessions from the host CLI.