T1564: Hide Artifacts
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.[1][2][3]
Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.[4]
Security context for executives and security teams
T1564: Hide Artifacts describes Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.(Citation: Sofacy Komplex Trojan)(Citation: Cyb...
Executive priority
T1564: Hide Artifacts is an official MITRE ATT&CK technique. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate T1564: Hide Artifacts by reviewing the official ATT&CK relationships, mapped tactics (stealth), supported platforms (ESXi, Linux, macOS, Office Suite), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
- Network, endpoint, and security-tool telemetry
Detection direction
- Validate whether T1564: Hide Artifacts appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Hide Artifacts
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.[1][2][3]
Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.[4]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Related techniques
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1564.012 | File/Path ExclusionsSub-technique | File/Path Exclusions subtechnique of this object. |
| Enterprise | T1564.008 | Email Hiding RulesSub-technique | Email Hiding Rules subtechnique of this object. |
| Enterprise | T1564.003 | Hidden WindowSub-technique | Hidden Window subtechnique of this object. |
| Enterprise | T1564.011 | Ignore Process InterruptsSub-technique | Ignore Process Interrupts subtechnique of this object. |
| Enterprise | T1564.002 | Hidden UsersSub-technique | Hidden Users subtechnique of this object. |
| Enterprise | T1564.014 | Extended AttributesSub-technique | Extended Attributes subtechnique of this object. |
| Enterprise | T1564.009 | Resource ForkingSub-technique | Resource Forking subtechnique of this object. |
| Enterprise | T1564.013 | Bind MountsSub-technique | Bind Mounts subtechnique of this object. |
| Enterprise | T1564.006 | Run Virtual InstanceSub-technique | Run Virtual Instance subtechnique of this object. |
| Enterprise | T1564.010 | Process Argument SpoofingSub-technique | Process Argument Spoofing subtechnique of this object. |
| Enterprise | T1564.001 | Hidden Files and DirectoriesSub-technique | Hidden Files and Directories subtechnique of this object. |
| Enterprise | T1564.004 | NTFS File AttributesSub-technique | NTFS File Attributes subtechnique of this object. |
| Enterprise | T1564.007 | VBA StompingSub-technique | VBA Stomping subtechnique of this object. |
| Enterprise | T1564.005 | Hidden File SystemSub-technique | Hidden File System subtechnique of this object. |
Groups, software, and campaigns
S1066: DarkTortilla
DarkTortilla is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. DarkTortilla has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.[1]
S9025: NOOPLDR
NOOPLDR is a shellcode loader with XML/C# and DLL versions that has been used by MirrorFace to load HiddenFace.[1]
S0482: Bundlore
S1011: Tarrask
S0402: OSX/Shlayer
OSX/Shlayer is a Trojan designed to install adware on macOS that was first discovered in 2018.[1][2]
S0670: WarzoneRAT
WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.[1][2]
S0332: Remcos
All related ATT&CK context
Mitigation direction
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | 7afbef43c47a… | ||
| 19.1 | 2.0 | Older bundle | 7afbef43c47a… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Sofacy Komplex Trojan
Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.
Open source URL - [2]Cybereason OSX Pirrit
Amit Serper. (2016). Cybereason Lab Analysis OSX.Pirrit. Retrieved December 10, 2021.
Open source URL - [3]MalwareBytes ADS July 2015
Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.
Open source URL - [4]Sophos Ragnar May 2020
SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.
Open source URL - [5]mitre-attackT1564Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
