Esc
Content Filtering
Definition
Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputing a sanitized version.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 14 techniques in this category, Content Filtering.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Content Filtering | D3-CF | Content Filtering techniques aid in the process of analyzing an input file for malicious or erroneous content and outputing a sanitized version. | |
| - File Format Verification | D3-FFV | Verifying that a file conforms to its expected format specifications | |
| - File Metadata Consistency Validation | D3-FMCV | The process of validating the consistency between a file's metadata and its actual content, ensuring that elements like declared lengths, pointers, and checksums accurately describe the file's content. | |
| - File Metadata Value Verification | D3-FMVV | The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification. | |
| - Content Rebuild | D3-CNR | Rebuild the file according to the spec so any unreferenced components or objects are removed. | Content Reconstruction |
| - File Content Decompression Checking | D3-FCDC | Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge | |
| - Content Format Conversion | D3-CFC | Content format conversion is mechanical transformation from one format to another which may be normalization or specifically flattening. | |
| - Content Quarantine | D3-CQ | Transfer content that does not comply with policy to a quarantine zone. | |
| - Content Excision | D3-CNE | Removing specific, potentially malicious, parts of content | |
| - File Internal Structure Verification | D3-FISV | The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification. | |
| - Content Validation | D3-CV | Verify and validate contents complies with policy | |
| - File Magic Byte Verification | D3-FMBV | Utilizing the magic number to verify the file | |
| - Content Substitution | D3-CNS | Modifies specific digital content information by replacing it with something else. | |
| - Content Modification | D3-CM | Modify content that does not comply with policy. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Privilege Escalation
Create or Modify System Process
Event Triggered Execution
Process Injection
Boot or Logon Autostart Execution
Scheduled Task/Job
Boot or Logon Initialization Scripts
Abuse Elevation Control Mechanism
Persistence
Office Application Startup
Event Triggered Execution
Modify Authentication Process
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Server Software Component
Execution
Command and Scripting Interpreter
Hijack Execution Flow
Scheduled Task/Job
Trusted Developer Utilities Proxy Execution
User Execution
Software Deployment Tools
Stealth
XSL Script Processing
Process Injection
System Binary Proxy Execution
Hijack Execution Flow
Rootkit
Masquerading
Obfuscated Files or Information
Hide Artifacts
Impair Defenses
Trusted Developer Utilities Proxy Execution
Deobfuscate/Decode Files or Information
Indicator Removal
Credential Access
Modify Authentication Process
Credentials from Password Stores
OS Credential Dumping
Forced Authentication
Unsecured Credentials
Steal or Forge Authentication Certificates
Defense Impairment
Modify Authentication Process
Subvert Trust Controls
Collection
Archive Collected Data
Data from Local System
Email Collection
Automated Collection
Data Staged
Discovery
System Owner/User Discovery
Remote System Discovery
File and Directory Discovery
System Network Configuration Discovery
Software Discovery
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Lateral Movement
Internal Spearphishing
Software Deployment Tools
References
All
Patent
The following references were used to develop the Content Filtering knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Method For Content Disarm and Reconstruction
Reference Type: Patent Organization: OPSWAT, Inc. Author: Taeil Goh, Vinh Nguyen Xuan Lam, Nhut Minh Ngo, Dung Huu Nguyen