Esc
File Format Verification
Definition
Verifying that a file conforms to its expected format specifications
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 6 techniques in this category, File Format Verification.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| File Format Verification | D3-FFV | Verifying that a file conforms to its expected format specifications | |
| - File Metadata Consistency Validation | D3-FMCV | The process of validating the consistency between a file's metadata and its actual content, ensuring that elements like declared lengths, pointers, and checksums accurately describe the file's content. | |
| - File Metadata Value Verification | D3-FMVV | The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification. | |
| - File Content Decompression Checking | D3-FCDC | Checking if compressed or encoded data sections can be successfully decompressed or decoded. Can follow with further analysis with semantic knowledge | |
| - File Internal Structure Verification | D3-FISV | The process of checking specific static values within a file, such as file signatures or magic numbers, to ensure they match the expected values defined by the file format specification. | |
| - File Magic Byte Verification | D3-FMBV | Utilizing the magic number to verify the file |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Collection
Data from Local System
Email Collection
Archive Collected Data
Automated Collection
Data Staged
Persistence
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Modify Authentication Process
Create or Modify System Process
Server Software Component
Event Triggered Execution
Office Application Startup
Scheduled Task/Job
Privilege Escalation
Boot or Logon Autostart Execution
Boot or Logon Initialization Scripts
Abuse Elevation Control Mechanism
Create or Modify System Process
Event Triggered Execution
Process Injection
Scheduled Task/Job
Stealth
System Binary Proxy Execution
Impair Defenses
Hijack Execution Flow
Hide Artifacts
Trusted Developer Utilities Proxy Execution
Process Injection
Masquerading
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Indicator Removal
Rootkit
XSL Script Processing
Discovery
Remote System Discovery
File and Directory Discovery
System Network Configuration Discovery
System Owner/User Discovery
Execution
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
User Execution
Software Deployment Tools
Command and Scripting Interpreter
Scheduled Task/Job
Credential Access
Modify Authentication Process
Unsecured Credentials
Steal or Forge Authentication Certificates
OS Credential Dumping
Forced Authentication
Credentials from Password Stores
Defense Impairment
Modify Authentication Process
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Lateral Movement
Internal Spearphishing
Software Deployment Tools
References
All
Patent
The following references were used to develop the File Format Verification knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
File Security Using FIle Format Validation
Reference Type: Patent Organization: OPSWAT, Inc. Author: Benjamin Czarny, Yiyi Miao, Jianpeng Mo