ManySignal
T1027 MITRE ATT&CK

T1027 Obfuscated Files or Information — Detection & Response

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses, whether hiding a malicious payload from AV signature scanning, defeating email gateway inspection, or camouflaging command execution from EDR and script logging.

Coverage at a glance

Detections shipped
5
Avg. verdict time
< 5 min
Data sources
4+

Threat context

How adversaries use T1027 Obfuscated Files or Information — Detection & Response

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses, whether hiding a malicious payload from AV signature scanning, defeating email gateway inspection, or camouflaging command execution from EDR and script logging.

Obfuscation is nearly universal in modern intrusions because it directly defeats the static-analysis layer of most defenses. Initial-access payloads arrive HTML-smuggled inside SVG or HTML attachments that reassemble a ZIP or ISO in the browser, sidestepping email gateway scanning entirely (used heavily by Qakbot, Pikabot, and multiple ransomware affiliates). PowerShell and cmd command lines are obfuscated with base64 encoding, string concatenation, format-string reordering, and character substitution (Invoke-Obfuscation, PSAmsi bypass patterns). Second-stage payloads are packed with commercial and custom packers (UPX, Themida, VMProtect), and increasingly stored fileless — in registry values, WMI class properties, or scheduled task actions — to defeat disk-based scanning. Steganographic techniques hide payloads inside PNG/JPEG images or, more recently, inside benign-looking JSON blobs served from CDNs.

Detections ManySignal ships

Ready-to-deploy detection rules

Rule name Severity Data source

High-Entropy Attachment or Download

An email attachment or downloaded file whose Shannon entropy exceeds ~7.5 bits/byte and whose declared MIME type does not match content magic bytes, indicative of packing, encryption, or a container hiding an executable.

Medium Email gateway / Web proxy

PowerShell Command Obfuscation — Base64 + Concatenation + Invoke-Expression

Script block contains FromBase64String, Convert.FromBase64String, or heavy string concatenation feeding Invoke-Expression / IEX / '&' invocation, matching Invoke-Obfuscation output patterns.

High PowerShell 4104 script block logs

HTML Smuggling — SVG or HTML With Embedded JavaScript Blob Reassembly

HTML or SVG document containing atob(), Blob([...]), and URL.createObjectURL() sequences that reconstruct a binary in-browser and trigger a download — the signature pattern of HTML smuggling kits used by Nobelium, Qakbot, and Pikabot.

High Email gateway / Web proxy

Packed Executable From Suspicious Parent Process

A newly-written PE file with high section entropy, few imports, and packer artifacts (UPX0/UPX1 sections, Themida markers) executed as a child of Office, browser, or mail client processes.

High EDR / Sysmon

Fileless Persistence — Large Base64 Blob in Registry or WMI Property

Registry value or WMI class property exceeding several KB containing base64 or hex-encoded content, typically the storage location for a fileless payload that is loaded and executed reflectively at trigger time.

Critical Sysmon Event ID 13 / WMI-Activity logs

T1027 Obfuscated Files or Information — Detection & Response: frequently asked questions

Why is obfuscation detection based on entropy rather than signatures?

Obfuscated payloads by definition change their static byte pattern on every build, so signatures fail. Entropy, structural features (section counts, import table size), and behavioral markers (in-memory unpacking, AMSI decode content) are invariant properties of obfuscation itself and remain detectable even when the payload is novel.

How does ManySignal handle HTML smuggling?

ManySignal inspects email and web-download content for the reassembly primitives (atob + Blob + createObjectURL, or SVG script tags reconstructing binaries) and correlates them with the resulting endpoint activity — the child process spawned from the browser, the disk write of the reassembled ISO, and the mark-of-the-web state of the dropped file. This chain is a high-confidence signal even when the final payload is unknown.

Does Constrained Language Mode actually stop obfuscated PowerShell?

Yes — CLM disables Add-Type, .NET reflection, and COM object instantiation, which are the primitives that virtually every obfuscated PowerShell loader depends on. Combined with WDAC enforcement so attackers cannot simply drop a full-language powershell.exe, CLM breaks the vast majority of T1027.010 payloads. It does not stop obfuscation in other interpreters (cmd, wscript, Python), which need their own controls.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.