Esc
Software Packing - T1027.002
(ATT&CK® Technique)
Definition
Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing or encrypting an executable. Packing an executable changes the file signature in an attempt to avoid signature-based detection. Most decompression techniques decompress the executable code in memory. Virtual machine software protection translates an executable's original code into a special format that only a special virtual machine can run. A virtual machine is then called to run this code.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.