Tactic.View on attack.mitre.org
The adversary is trying to hide and conceal their actions, appearing as normal behavior.
Stealth consists of techniques that reduce the likelihood of detection by blending in with legitimate activity or minimizing observable signals. These techniques are characterized by concealment behaviors, such as avoiding, obfuscating, or mimicking normal operations, without modifying security controls or compromising collection and monitoring feeds. The goal is to remain indistinguishable from benign activity while leaving defensive systems intact.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1006 | Direct Volume Access | 0 | 5 |
| T1014 | Rootkit | 0 | 32 |
| T1027 | Obfuscated Files or Information | 18 | 815 |
| T1036 | Masquerading | 12 | 437 |
| T1055 | Process Injection | 12 | 239 |
| T1070 | Indicator Removal | 8 | 443 |
| T1078 | Valid Accounts | 4 | 149 |
| T1127 | Trusted Developer Utilities Proxy Execution | 3 | 5 |
| T1134 | Access Token Manipulation | 5 | 67 |
| T1140 | Deobfuscate/Decode Files or Information | 0 | 353 |
| T1197 | BITS Jobs | 0 | 13 |
| T1202 | Indirect Command Execution | 0 | 4 |
| T1205 | Traffic Signaling | 2 | 33 |
| T1211 | Exploitation for Stealth | 0 | 2 |
| T1216 | System Script Proxy Execution | 2 | 1 |
| T1218 | System Binary Proxy Execution | 14 | 230 |
| T1220 | XSL Script Processing | 0 | 4 |
| T1221 | Template Injection | 0 | 12 |
| T1480 | Execution Guardrails | 2 | 80 |
| T1497 | Virtualization/Sandbox Evasion | 3 | 153 |
| T1535 | Unused/Unsupported Cloud Regions | 0 | 0 |
| T1542 | Pre-OS Boot | 5 | 14 |
| T1564 | Hide Artifacts | 14 | 174 |
| T1574 | Hijack Execution Flow | 12 | 152 |
| T1612 | Build Image on Host | 0 | 0 |
| T1620 | Reflective Code Loading | 0 | 32 |
| T1622 | Debugger Evasion | 0 | 26 |
| T1678 | Delay Execution | 0 | 20 |
| T1679 | Selective Exclusion | 0 | 7 |
| T1684 | Social Engineering | 2 | 22 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.