File Content Decompression Checking
Definition
Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge
How it works
Some file formats such as JPEGs include encoded or compressed sections. This technique verfies that those expected sections are present and can be properly decoded according to the spec.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related ATT&CK Techniques:
These offensive techniques are determined related because of the way this defensive technique,, , , and .
References
The following references were used to develop the File Content Decompression Checking knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)