T1027 Obfuscated Files or Information — Detection & Response
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses, whether hiding a malicious payload from AV signature scanning, defeating email gateway inspection, or camouflaging command execution from EDR and script logging.
Coverage at a glance
- Detections shipped
- 5
- Avg. verdict time
- < 5 min
- Data sources
- 4+
Threat context
How adversaries use T1027 Obfuscated Files or Information — Detection & Response
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses, whether hiding a malicious payload from AV signature scanning, defeating email gateway inspection, or camouflaging command execution from EDR and script logging.
Obfuscation is nearly universal in modern intrusions because it directly defeats the static-analysis layer of most defenses. Initial-access payloads arrive HTML-smuggled inside SVG or HTML attachments that reassemble a ZIP or ISO in the browser, sidestepping email gateway scanning entirely (used heavily by Qakbot, Pikabot, and multiple ransomware affiliates). PowerShell and cmd command lines are obfuscated with base64 encoding, string concatenation, format-string reordering, and character substitution (Invoke-Obfuscation, PSAmsi bypass patterns). Second-stage payloads are packed with commercial and custom packers (UPX, Themida, VMProtect), and increasingly stored fileless — in registry values, WMI class properties, or scheduled task actions — to defeat disk-based scanning. Steganographic techniques hide payloads inside PNG/JPEG images or, more recently, inside benign-looking JSON blobs served from CDNs.
Detections ManySignal ships
Ready-to-deploy detection rules
| Rule name | Severity | Data source |
|---|---|---|
| High-Entropy Attachment or Download An email attachment or downloaded file whose Shannon entropy exceeds ~7.5 bits/byte and whose declared MIME type does not match content magic bytes, indicative of packing, encryption, or a container hiding an executable. | Medium | Email gateway / Web proxy |
| PowerShell Command Obfuscation — Base64 + Concatenation + Invoke-Expression Script block contains FromBase64String, Convert.FromBase64String, or heavy string concatenation feeding Invoke-Expression / IEX / '&' invocation, matching Invoke-Obfuscation output patterns. | High | PowerShell 4104 script block logs |
| HTML Smuggling — SVG or HTML With Embedded JavaScript Blob Reassembly HTML or SVG document containing atob(), Blob([...]), and URL.createObjectURL() sequences that reconstruct a binary in-browser and trigger a download — the signature pattern of HTML smuggling kits used by Nobelium, Qakbot, and Pikabot. | High | Email gateway / Web proxy |
| Packed Executable From Suspicious Parent Process A newly-written PE file with high section entropy, few imports, and packer artifacts (UPX0/UPX1 sections, Themida markers) executed as a child of Office, browser, or mail client processes. | High | EDR / Sysmon |
| Fileless Persistence — Large Base64 Blob in Registry or WMI Property Registry value or WMI class property exceeding several KB containing base64 or hex-encoded content, typically the storage location for a fileless payload that is loaded and executed reflectively at trigger time. | Critical | Sysmon Event ID 13 / WMI-Activity logs |
Related techniques and tactics
T1078 Valid Accounts — Detection & Response
ATT&CK Technique
T1110 Brute Force — Detection & Response
ATT&CK Technique
T1566 Phishing — Detection & Response
ATT&CK Technique
T1059 Command and Scripting Interpreter — Detection & Response
ATT&CK Technique
T1053 Scheduled Task/Job — Detection & Response
ATT&CK Technique
T1548 Abuse Elevation Control Mechanism — Detection & Response
ATT&CK Technique
T1068 Exploitation for Privilege Escalation — Detection & Response
ATT&CK Technique
T1134 Access Token Manipulation — Detection & Response
ATT&CK Technique
T1098 Account Manipulation — Detection & Response
ATT&CK Technique
T1136 Create Account — Detection & Response
ATT&CK Technique
T1556 Modify Authentication Process — Detection & Response
ATT&CK Technique
T1621 Multi-Factor Authentication Request Generation — Detection & Response
ATT&CK Technique
T1027 Obfuscated Files or Information — Detection & Response: frequently asked questions
Why is obfuscation detection based on entropy rather than signatures?
Obfuscated payloads by definition change their static byte pattern on every build, so signatures fail. Entropy, structural features (section counts, import table size), and behavioral markers (in-memory unpacking, AMSI decode content) are invariant properties of obfuscation itself and remain detectable even when the payload is novel.
How does ManySignal handle HTML smuggling?
ManySignal inspects email and web-download content for the reassembly primitives (atob + Blob + createObjectURL, or SVG script tags reconstructing binaries) and correlates them with the resulting endpoint activity — the child process spawned from the browser, the disk write of the reassembled ISO, and the mark-of-the-web state of the dropped file. This chain is a high-confidence signal even when the final payload is unknown.
Does Constrained Language Mode actually stop obfuscated PowerShell?
Yes — CLM disables Add-Type, .NET reflection, and COM object instantiation, which are the primitives that virtually every obfuscated PowerShell loader depends on. Combined with WDAC enforcement so attackers cannot simply drop a full-language powershell.exe, CLM breaks the vast majority of T1027.010 payloads. It does not stop obfuscation in other interpreters (cmd, wscript, Python), which need their own controls.
See the agentic SOC in action
Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.