Esc
Emulated File Analysis
Definition
Emulating instructions in a file looking for specific patterns.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , and .
Persistence
Server Software Component
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Event Triggered Execution
Office Application Startup
Privilege Escalation
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Event Triggered Execution
Abuse Elevation Control Mechanism
Process Injection
Stealth
Impair Defenses
Obfuscated Files or Information
XSL Script Processing
Deobfuscate/Decode Files or Information
Hijack Execution Flow
Masquerading
System Binary Proxy Execution
Hide Artifacts
Process Injection
Discovery
System Network Configuration Discovery
Execution
User Execution
Hijack Execution Flow
Command and Scripting Interpreter
Lateral Movement
Internal Spearphishing
References
All
Academic Paper
The following references were used to develop the Emulated File Analysis knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Network-level polymorphic shellcode detection using emulation
Reference Type: Academic Paper Author: Michalis Polychronakis