Umbra Wiki attack-pattern attack-pattern/CAPEC-655
Back to wiki

CAPEC-655 — Avoid Security Tool Identification by Adding Data

provenance: imported · ATT&CK: T1027.001

CAPEC-655: Avoid Security Tool Identification by Adding Data

MITRE CAPEC attack pattern

Status Draft
Typical severity High
Likelihood of attack High
Catalogue CAPEC 3.9 (2023-01-24)

Description

An adversary adds data to a file to increase the file size beyond what security tools are capable of handling in an attempt to mask their actions. In addition to this, adding data to a file also changes the file's hash, frustrating security tools that look for known bad files by their hash.

Where this sits in the chain

A finding maps to a weakness (CWE), a weakness is exploited by an attack pattern (CAPEC), and an attack pattern shows up in ATT&CK as observed adversary behaviour. This page is the middle hop.

ATT&CK techniques: T1027.001

Consequences

  • Accountability: Hide Activities, Bypass Protection Mechanism
  • Integrity: Modify Data

Source