Exploitation for Stealth

T1211

Technique.View on attack.mitre.org

About this technique

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Adversaries may exploit a system or application vulnerability to avoid detection while maintaining access within an environment. Exploitation occurs when an adversary leverages a programming flaw to execute code in a manner that minimizes visibility or blends in with legitimate activity.

Rather than directly disabling defenses, adversaries may use exploitation to circumvent monitoring and logging mechanisms. This can include abusing vulnerabilities in logging pipelines, security tools, or cloud infrastructure to evade audit trails, suppress alerts, or operate without generating telemetry.

Adversaries may identify these opportunities through prior reconnaissance or by performing discovery of security controls after initial access. In some cases, vulnerabilities in SaaS or public cloud environments may be exploited to evade logging, obscure activity, or deploy infrastructure that remains hidden from standard monitoring tools.

Detection rules5

Rules on DetectionCode tagged with T1211.

Sigma4

RuleLevelLog source
Audit CVE Eventcriticalwindows / NULL
Microsoft Malware Protection Engine Crashhighwindows / NULL
Microsoft Malware Protection Engine Crash - WERhighwindows / NULL
Writing Of Malicious Files To The Fonts Foldermediumwindows / process_creation

Splunk1

RuleTypeRiskData source
Windows Defender Threat Detected on Kernel Object PathTTPNULLWindows Event Log Defender 1116, Windows Event Log Defender 1117

Groups2

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples2

Groups2

Used byProcedure example
GroupAPT28

APT28 has used CVE-2015-4902 to bypass security features.

GroupVelvet Ant

Velvet Ant exploited CVE-2024-20399 in Cisco Switches to which the threat actor was already able to authenticate in order to escape the NX-OS command line interface and gain access to the underlying operating system for arbitrary command execution.

References2

  1. Bypassing CloudTrail in AWS Service Catalog Open source
    Nick Frichette. (2023, March 20). Bypassing CloudTrail in AWS Service Catalog, and Other Logging Research. Retrieved September 18, 2023.
  2. GhostToken GCP flaw Open source
    Sergiu Gatlan. (2023, April 21). GhostToken GCP flaw let attackers backdoor Google accounts. Retrieved September 18, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.