LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1564: Hide Artifacts

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.[1][2][3]

Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.[4]

EnterpriseT1564TechniqueObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Hide Artifacts is important because it describes the ways an intruder can make malicious files, accounts, windows, email rules, process details, file metadata, or virtualized activity less visible to users and security tools. For leaders, the practical issue is not one specific trick; it is whether the organization can still find suspicious activity when adversaries abuse normal operating system, Office, filesystem, and virtualization features intended for administration or usability.

Executive priority

Treat this as a visibility and assurance problem across endpoints, email/Office environments, Linux/macOS/Windows systems, and ESXi where in scope. The priority question is whether security investments actually observe hidden artifacts rather than only standard file listings, user-visible windows, or basic process logs. This technique also supports audit and incident response readiness: teams need evidence that hidden files, hidden accounts, email hiding rules, AV/file exclusions, virtual instances, and unusual filesystem metadata can be reviewed during investigations.

Technical view

ATT&CK provides no official detection text for T1564, so validation should be driven by the related detection strategy DET0502 and the sub-techniques. SOC and IR teams should test coverage for hidden files/directories, hidden users, hidden windows, NTFS attributes and alternate data streams, hidden file systems, virtual instances, VBA stomping, email hiding rules, resource forks, process argument spoofing, ignored interrupts, file/path exclusions, bind mounts, and extended attributes. Because supported platforms include ESXi, Linux, macOS, Office Suite, and Windows, detection engineering should not assume one endpoint telemetry source is sufficient.

Likely telemetry

  • Endpoint file creation, modification, attribute, and metadata events across Windows, Linux, and macOS
  • Account creation and account attribute changes, including attributes that affect login or visibility
  • Process creation telemetry, command-line capture, and where available evidence of command-line or argument inconsistencies
  • Filesystem inspection data such as NTFS attributes/alternate data streams, macOS resource forks, Linux/macOS extended attributes, bind mounts, and hidden filesystem indicators
  • Email and Office administrative logs showing inbox rule creation or modification

Detection direction

  • Map detections to the sub-techniques rather than treating T1564 as a single alert condition; each hiding method has different evidence and blind spots.
  • Validate that endpoint tools collect hidden metadata, alternate streams, extended attributes, resource forks, bind mounts, and file/path exclusions, not just visible file paths.
  • Tune detections with administrative baselines because many hiding features have legitimate operating system or administrator use cases.
  • For Office Suite coverage, confirm whether email rule changes and suspicious embedded VBA document characteristics are logged and reviewable.
  • For ESXi and virtualization-related scope, confirm that monitoring can see virtual instances and related activity rather than only host-level endpoint events.

Mitigation priorities

  • Start with audit readiness: ensure systems record activity and configuration changes needed to review hidden artifacts, aligned to M1047 Audit.
  • Limit unauthorized software installation using allowlists, software restriction policies, endpoint management, and least privilege principles where appropriate, aligned to M1033 Limit Software Installation.
  • Deploy and maintain antimalware across relevant endpoints, while also verifying that exclusions and blind spots are governed, aligned to M1049 Antivirus/Antimalware.
  • For internally developed applications or tooling, apply secure development guidance where relevant so applications do not introduce avoidable weaknesses or unsafe artifact-handling behavior, aligned to M1013 Application Developer Guidance.
  • Prioritize controls by platform exposure: Windows filesystem and process visibility, macOS/Linux metadata and hidden file behaviors, Office/email rule auditing, and ESXi/virtualization monitoring where those platforms are used.
Additional notes and limits

This parent technique is broad and its defensive value comes from decomposing it into the listed sub-techniques. The supplied relationships show one detection strategy, four mitigations, fourteen sub-techniques, and several software examples. Use those relationships to guide coverage reviews, purple-team validation, and incident response checklists without assuming any specific adversary is present.

MITRE does not provide official detection text for this object in the supplied fields. The object describes possible hiding behaviors and supported platforms, but local telemetry, product capabilities, logging configuration, and administrative practices determine actual detection and response coverage. No active exploitation, customer exposure, or guaranteed detection should be inferred from this ATT&CK entry alone.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Hide Artifacts

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and administrative task execution, to avoid disrupting user work environments and prevent users from changing files or features on the system. Adversaries may abuse these features to hide artifacts such as files, directories, user accounts, or other system activity to evade detection.[1][2][3]

Adversaries may also attempt to hide artifacts associated with malicious behavior by creating computing regions that are isolated from common security instrumentation, such as through the use of virtualization technology.[4]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Related techniques

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

14 rows
DomainIDNameRelationship / procedure
EnterpriseT1564.003Hidden WindowSub-techniqueHidden Window subtechnique of this object.
EnterpriseT1564.011Ignore Process InterruptsSub-techniqueIgnore Process Interrupts subtechnique of this object.
EnterpriseT1564.002Hidden UsersSub-techniqueHidden Users subtechnique of this object.
EnterpriseT1564.012File/Path ExclusionsSub-techniqueFile/Path Exclusions subtechnique of this object.
EnterpriseT1564.014Extended AttributesSub-techniqueExtended Attributes subtechnique of this object.
EnterpriseT1564.008Email Hiding RulesSub-techniqueEmail Hiding Rules subtechnique of this object.
EnterpriseT1564.009Resource ForkingSub-techniqueResource Forking subtechnique of this object.
EnterpriseT1564.013Bind MountsSub-techniqueBind Mounts subtechnique of this object.
EnterpriseT1564.006Run Virtual InstanceSub-techniqueRun Virtual Instance subtechnique of this object.
EnterpriseT1564.010Process Argument SpoofingSub-techniqueProcess Argument Spoofing subtechnique of this object.
EnterpriseT1564.001Hidden Files and DirectoriesSub-techniqueHidden Files and Directories subtechnique of this object.
EnterpriseT1564.004NTFS File AttributesSub-techniqueNTFS File Attributes subtechnique of this object.
EnterpriseT1564.007VBA StompingSub-techniqueVBA Stomping subtechnique of this object.
EnterpriseT1564.005Hidden File SystemSub-techniqueHidden File System subtechnique of this object.
Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0482: Bundlore

Bundlore is adware written for macOS that has been in use since at least 2015. Though categorized as adware, Bundlore has many features associated with more traditional backdoors.[1]

macOS
MalwareEnterprise

S0670: WarzoneRAT

WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.[1][2]

Windows
ToolEnterprise

S0332: Remcos

Remcos is a closed-source tool that is marketed as a remote control and surveillance software by a company called Breaking Security. Remcos has been observed being used in malware campaigns.[1][2]

Windows
MalwareEnterprise

S1011: Tarrask

Tarrask is malware that has been used by HAFNIUM since at least August 2021. Tarrask was designed to evade digital defenses and maintain persistence by generating concealed scheduled tasks.[1]

Windows
Relationship explorer

All related ATT&CK context

Mitigations

Mitigation direction

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
7afbef43c47af552...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.12.0Current bundle7afbef43c47a…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Sofacy Komplex Trojan

    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

    Open source URL
  2. [2]
    Cybereason OSX Pirrit

    Amit Serper. (2016). Cybereason Lab Analysis OSX.Pirrit. Retrieved December 10, 2021.

    Open source URL
  3. [3]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  4. [4]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  5. [5]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  6. [6]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  7. [7]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  8. [8]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  9. [9]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  10. [10]
    Microsoft File Folder Exclusions

    Microsoft. (2024, February 27). Contextual file and folder exclusions. Retrieved March 29, 2024.

    Open source URL
  11. [11]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  12. [12]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  13. [13]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
  14. [14]
    Cybereason OSX Pirrit

    Amit Serper. (2016). Cybereason Lab Analysis OSX.Pirrit. Retrieved December 10, 2021.

    Open source URL
  15. [15]
    Cybereason OSX Pirrit

    Amit Serper. (2016). Cybereason Lab Analysis OSX.Pirrit. Retrieved December 10, 2021.

    Open source URL
  16. [16]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  17. [17]
    MalwareBytes ADS July 2015

    Arntz, P. (2015, July 22). Introduction to Alternate Data Streams. Retrieved March 21, 2018.

    Open source URL
  18. [18]
    Sofacy Komplex Trojan

    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

    Open source URL
  19. [19]
    Sofacy Komplex Trojan

    Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.

    Open source URL
  20. [20]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  21. [21]
    Sophos Ragnar May 2020

    SophosLabs. (2020, May 21). Ragnar Locker ransomware deploys virtual machine to dodge security. Retrieved June 29, 2020.

    Open source URL
  22. [22]
    mitre-attackT1564
    Open source URL
  23. [23]
    mitre-attackT1564
    Open source URL
  24. [24]
    mitre-attackT1564
    Open source URL
  25. [25]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  26. [26]
    Shlayer jamf gatekeeper bypass 2021

    Jaron Bradley. (2021, April 26). Shlayer malware abusing Gatekeeper bypass on macOS. Retrieved September 22, 2021.

    Open source URL
  27. [27]
    sentinelone shlayer to zshlayer

    Phil Stokes. (2020, September 8). Coming Out of Your Shell: From Shlayer to ZShlayer. Retrieved September 13, 2021.

    Open source URL
  28. [28]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  29. [29]
    20 macOS Common Tools and Techniques

    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved August 23, 2021.

    Open source URL
  30. [30]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  31. [31]
    Secureworks DarkTortilla Aug 2022

    Secureworks Counter Threat Unit Research Team. (2022, August 17). DarkTortilla Malware Analysis. Retrieved November 3, 2022.

    Open source URL
  32. [32]
    Microsoft File Folder Exclusions

    Microsoft. (2024, February 27). Contextual file and folder exclusions. Retrieved March 29, 2024.

    Open source URL
  33. [33]
    Fortinet Remcos Campaign NOV 2024

    Zhang, X. (2024, November 8). New Campaign Uses Remcos RAT to Exploit Victims. Retrieved April 16, 2026.

    Open source URL
  34. [34]
    Tarrask scheduled task

    Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.

    Open source URL
  35. [35]
    JPCERT MirrorFace JUL 2024

    Tomonaga, S. (2024, July 16). MirrorFace Attack against Japanese Organisations. Retrieved April 17, 2026.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.