Esc
Emulated File Analysis
Definition
Emulating instructions in a file looking for specific patterns.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , and .
Stealth
Process Injection
Deobfuscate/Decode Files or Information
Hijack Execution Flow
Masquerading
System Binary Proxy Execution
Hide Artifacts
Impair Defenses
Obfuscated Files or Information
XSL Script Processing
Execution
User Execution
Hijack Execution Flow
Command and Scripting Interpreter
Persistence
Office Application Startup
Event Triggered Execution
Boot or Logon Initialization Scripts
Boot or Logon Autostart Execution
Server Software Component
Lateral Movement
Internal Spearphishing
Privilege Escalation
Event Triggered Execution
Boot or Logon Initialization Scripts
Process Injection
Boot or Logon Autostart Execution
Abuse Elevation Control Mechanism
Discovery
System Network Configuration Discovery
References
All
Academic Paper
The following references were used to develop the Emulated File Analysis knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Network-level polymorphic shellcode detection using emulation
Reference Type: Academic Paper Author: Michalis Polychronakis