T1564Tactic: Defense EvasionOfficial MITRE ATT&CK Page

T1564: Hide Artifacts

Adversaries may attempt to hide artifacts and malicious actions associated with behaviors to avoid detection by users and security tools.

Total Capable Binaries: 21
Windows: 21
Linux: 0
macOS: 0

Living-off-the-Land Matrix for T1564

Across 21 verified binaries
Windows0 payloads

Cmd.exe

The command-line interpreter in Windows

Windows1 payloads

DeviceCredentialDeployment.exe

Device Credential Deployment

Sample Attack Vector:
DeviceCredentialDeployment
Windows0 payloads

Diantz.exe

Binary that package existing files into a cabinet (.cab) file

Windows0 payloads

Esentutl.exe

Binary for working with Microsoft Joint Engine Technology (JET) database

Windows0 payloads

Expand.exe

Binary that expands one or more compressed files

Windows0 payloads

Extrac32.exe

Extract to ADS, copy or overwrite a file with Extrac32.exe

Windows0 payloads

Findstr.exe

Write to ADS, discover, or download files with Findstr.exe

Windows0 payloads

Forfiles.exe

Selects and executes a command on a file or set of files. This command is useful for batch processing.

Windows0 payloads

Makecab.exe

Binary to package existing files into a cabinet (.cab) file

Windows0 payloads

Mavinject.exe

Used by App-v in Windows

Windows0 payloads

MpCmdRun.exe

Binary part of Windows Defender. Used to manage settings in Windows Defender

Windows0 payloads

Print.exe

Used by Windows to send files to the printer

Windows0 payloads

PrintBrm.exe

Printer Migration Command-Line Tool

Windows0 payloads

Reg.exe

Used to manipulate the registry

Windows0 payloads

Regedit.exe

Used by Windows to manipulate registry

Windows0 payloads

Regini.exe

Used to manipulate the registry

Windows0 payloads

Sc.exe

Used by Windows to manage services

Windows0 payloads

Tar.exe

Used by Windows to extract and create archives.

Windows0 payloads

Wscript.exe

Used by Windows to execute scripts

Windows6 payloads

msxsl.exe

Command line utility used to perform XSL transformations.

Sample Attack Vector:
msxsl.exe {PATH:.xml} {PATH:.xsl}
Windows0 payloads

wsb.exe

Windows Sandbox command-line interface. Creates, lists, controls, and executes commands inside Windows Sandbox sessions from the host CLI.

Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point