Files
brightmt 6933d9e896 Snake (#179)
* Update snake.md

Updated malware behaviors and descriptions.

* Update snake.md

Divided table to split out enhanced techniques

* Update software-packing.md

Added Snake

* Update self-deletion.md

Added Snake

* Update system-information-discovery.md

Added Snake

* Update keylogging.md

Added Snake

* Update screen-capture.md

* Update decode-data.md

Added Snake

* Update decrypt-data.md

Added Snake

* Update copy-file.md

Added Snake

* Update create-file.md

Added Snake

* Update delete-file.md

* Update crypto-library.md

Added Snake

* Update crypto-library.md

---------

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2025-04-03 17:46:24 -04:00
..
2024-05-01 16:09:33 -04:00
2023-09-20 15:57:32 -04:00
2024-05-01 16:09:33 -04:00
2024-05-01 16:09:33 -04:00
2024-05-01 16:09:33 -04:00
2024-10-02 11:48:36 -04:00
2024-05-01 16:09:33 -04:00
2023-09-20 15:57:32 -04:00
2024-05-01 16:09:33 -04:00
2025-04-03 17:46:24 -04:00

ID OB0006
Created 1 August 2019
Last Modified 8 May 2023

Defense Evasion

Behaviors that enable malware to evade detection.

  • Alternative Installation Location B0027
  • Bootkit F0013
  • Bypass DEP B0037
  • Component Firmware F0009
  • Conditional Execution B0025
  • Covert Location B0040
  • Disable or Evade Security Tools F0004
  • Hide Artifacts E1564
  • Hidden Files and Directories F0005
  • Hijack Execution Flow F0015
  • Indicator Blocking F0006
  • Install Insecure or Malicious Configuration B0047
  • Modify Registry E1112
  • Obfuscated Files or Information E1027
  • Polymorphic Code B0029
  • Process Injection E1055
  • Rootkit E1014
  • Self Deletion F0007
  • Software Packing F0001