Esc
File Hashing
Definition
Employing file hash comparisons to detect known malware.
How it works
This technique requires a list of hashes to compare a file against.
Considerations
Performance on large files or very large numbers of files.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, .
Stealth
Obfuscated Files or Information
XSL Script Processing
Process Injection
System Binary Proxy Execution
Hijack Execution Flow
Rootkit
Masquerading
Hide Artifacts
Deobfuscate/Decode Files or Information
Indicator Removal
Impair Defenses
Trusted Developer Utilities Proxy Execution
Collection
Archive Collected Data
Automated Collection
Data Staged
Data from Local System
Email Collection
Discovery
System Network Configuration Discovery
File and Directory Discovery
System Owner/User Discovery
Remote System Discovery
Persistence
Office Application Startup
Event Triggered Execution
Modify Authentication Process
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Server Software Component
Execution
Command and Scripting Interpreter
Hijack Execution Flow
Scheduled Task/Job
User Execution
Software Deployment Tools
Trusted Developer Utilities Proxy Execution
Privilege Escalation
Event Triggered Execution
Process Injection
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Abuse Elevation Control Mechanism
Boot or Logon Initialization Scripts
Credential Access
Modify Authentication Process
OS Credential Dumping
Unsecured Credentials
Credentials from Password Stores
Forced Authentication
Steal or Forge Authentication Certificates
Defense Impairment
Modify Authentication Process
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Lateral Movement
Internal Spearphishing
Software Deployment Tools
References
All
Source Code
The following references were used to develop the File Hashing knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Online Hash Checker for Virustotal and Other Services
Reference Type: Source Code Author: Florian Roth
Source: