Esc
Content Rebuild
Definition
Rebuild the file according to the spec so any unreferenced components or objects are removed.
Synonyms: Content Reconstruction.How it works
If inputted content is divided up into components for further scrutiny, the components may be combined back afterwards in a safer state.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Privilege Escalation
Process Injection
Event Triggered Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Abuse Elevation Control Mechanism
Persistence
Event Triggered Execution
Create or Modify System Process
Scheduled Task/Job
Office Application Startup
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Modify Authentication Process
Server Software Component
Collection
Archive Collected Data
Data from Local System
Email Collection
Automated Collection
Data Staged
Stealth
Process Injection
Masquerading
Obfuscated Files or Information
Hide Artifacts
System Binary Proxy Execution
Impair Defenses
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
Deobfuscate/Decode Files or Information
Indicator Removal
Rootkit
XSL Script Processing
Execution
Scheduled Task/Job
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
User Execution
Software Deployment Tools
Command and Scripting Interpreter
Credential Access
Credentials from Password Stores
OS Credential Dumping
Forced Authentication
Modify Authentication Process
Unsecured Credentials
Steal or Forge Authentication Certificates
Discovery
System Owner/User Discovery
Remote System Discovery
File and Directory Discovery
System Network Configuration Discovery
Defense Impairment
Modify Authentication Process
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Lateral Movement
Internal Spearphishing
Software Deployment Tools
References
All
Patent
The following references were used to develop the Content Rebuild knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Method For Content Disarm and Reconstruction
Reference Type: Patent Organization: OPSWAT, Inc. Author: Taeil Goh, Vinh Nguyen Xuan Lam, Nhut Minh Ngo, Dung Huu Nguyen