// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE PUB-ENTDTG 0600Z
ColdReconTechniquesT1027
Technique T1027

Obfuscated Files or Information

CLEARED FOR PUBLIC RELEASE · OPEN-SOURCE INTELLIGENCE
Obfuscated Files or Information (T1027) — a Defense Evasion technique, observed in public incident reporting.
MITRE ATT&CKT1027
TacticDefense Evasion
Incidents on file25

Detection & mitigation

Monitor for suspicious script execution (wscript/cscript) spawning PowerShell with download cradle or encoded commands. Use AMSI and script block logging to detect obfuscated scripts; employ endpoint detection and response (EDR) to identify Agent Tesla behavior such as credential dumping and suspicious network connections.

Observed in the wild

Track this in real time.

ColdRecon watches the public signal so you don't have to — a daily brief and a live detection-coverage desk. Request clearance.

Request Clearance →