Meta tags:
Headings (most frequently used words):
subvert, trust, controls, of, mark, the, web, bypass, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques,
Text of the page (most frequently used words):
the (35), files (21), and (20), motw (14), file (12), retrieved (11), web (11), att (10), all (10), february (10), mark (10), container (9), with (9), t1553 (9), #bypass (8), are (7), enterprise (7), 2021 (7), iso (7), vhd (6), windows (6), 2022 (6), not (6), has (6), may (6), ics (5), mobile (5), none (5), data (5), techniques (5), 2020 (5), that (5), will (5), subvert (5), controls (5), trust (5), mitre (4), sub (4), explorer (4), for (4), image (4), ta505 (4), from (4), zone (4), identifier (4), name (4), disk (4), version (4), tagged (4), 2026 (3), use (3), cti (3), detection (3), mitigations (3), defenses (3), 2019 (3), vhdx (3), august (3), disable (3), mount (3), qakbot (3), december (3), security (3), internet (3), execution (3), smartscreen (3), protected (3), description (3), consider (3), 005 (3), ntfs (3), known (3), corporation (2), policy (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), march (2), associations (2), october (2), via (2), 2024 (2), threat (2), financial (2), deliver (2), beek (2), stream (2), mounting (2), archive (2), but (2), contained (2), view (2), analytic (2), extensions (2), this (2), can (2), order (2), feature (2), used (2), deploy (2), malicious (2), measures (2), apt38 (2), apt29 (2), modified (2), ads (2), amadey (2), technique (2), adversaries (2), abuse (2), formats (2), downloaded (2), within (2), after (2), extracted (2), mounted (2), run (2), specific (2), office (2), open (2), executables (2), code (2), signing (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, dormann, september, dangers, wdormann, disc, april, trend, micro, variety, servhelper, flawedammyy, kenefick, black, basta, ransomware, gang, infiltrates, networks, brute, ratel, cobalt, strike, 2023, seongsu, park, bluenoroff, introduces, new, methods, bypassing, eset, report, institute, profiling, group, continues, attack, sector, july, kennedy, zebra, gopher, clothing, russian, apt, uses, covid, lures, zebrocy, hegt, red, team, perspective, investigating, cybercriminals, november, microsoft, references, detects, extraction, zip, originated, whose, lack, tagging, correlates, creation, metadata, subsequent, unsigned, untrusted, binaries, launched, outside, an0712, detect, det0257, strategy, blocking, types, email, gateways, unregistering, prevention, m1038, disabling, auto, img, achieved, modifying, registry, values, related, automatic, burn, dialog, these, note, deactivate, functionality, itself, remove, program, m1042, mitigation, lnk, g0092, been, packaged, s0650, malware, g0082, embedded, images, html, evade, g0016, area, zero, s1025, procedure, examples, live, permalink, last, created, christiaan, christiaanbeek, contributors, platforms, defense, impairment, tactic, such, compressed, arj, gzip, payloads, marked, inherit, many, support, alternative, streams, them, treated, local, without, protections, when, they, hidden, alternate, named, value, cannot, perform, certain, actions, example, starting, processed, defender, compares, allowlist, well, trusted, prevent, warn, user, modification, 006, install, root, certificate, 004, sip, provider, hijacking, 003, 002, gatekeeper, 001, other, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
subvert trust controls mark of the web bypass sub technique t1553 005 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise subvert trust controls mark of the web bypass subvert trust controls mark of the web bypass other sub techniques of subvert trust controls 6 id name t1553 001 gatekeeper bypass t1553 002 code signing t1553 003 sip and trust provider hijacking t1553 004 install root certificate t1553 005 mark of the web bypass t1553 006 code signing policy modification adversaries may abuse specific file formats to subvert mark of the web motw controls in windows when files are downloaded from the internet they are tagged with a hidden ntfs alternate data stream ads named zone identifier with a specific value known as the motw 1 files that are tagged with motw are protected and cannot perform certain actions for example starting in ms office 10 if a ms office file has the motw it will open in protected view executables tagged with the motw will be processed by windows defender smartscreen that compares files with an allowlist of well known executables if the file is not known trusted smartscreen will prevent the execution and warn the user not to run it 2 3 4 adversaries may abuse container files such as compressed archive arj gzip and or disk image iso vhd file formats to deliver malicious payloads that may not be tagged with motw container files downloaded from the internet will be marked with motw but the files within may not inherit the motw after the container files are extracted and or mounted motw is a ntfs feature and many container files do not support ntfs alternative data streams after a container file is extracted and or mounted the files contained within them may be treated as local files on disk and run without protections 2 3 id t1553 005 sub technique of t1553 ⓘ tactic defense impairment ⓘ platforms windows contributors christiaan beek christiaanbeek version 2 0 created 22 february 2021 last modified 12 may 2026 version permalink live version procedure examples id name description s1025 amadey amadey has modified the zone identifier in the ads area to zero 5 g0016 apt29 apt29 has embedded iso images and vhdx files in html to evade mark of the web 6 g0082 apt38 apt38 has used iso and vhd files to deploy malware and to bypass mark of the web motw security measures 7 s0650 qakbot qakbot has been packaged in iso files in order to bypass mark of the web motw security measures 8 g0092 ta505 ta505 has used iso files to deploy malicious lnk files 9 mitigations id mitigation description m1042 disable or remove feature or program consider disabling auto mounting of disk image files i e iso img vhd and vhdx this can be achieved by modifying the registry values related to the windows explorer file associations in order to disable the automatic explorer mount and burn dialog for these file extensions note this will not deactivate the mount functionality itself 10 m1038 execution prevention consider blocking container file types at web and or email gateways consider unregistering container file extensions in windows file explorer 11 detection strategy id name analytic id analytic description det0257 detect mark of the web motw bypass via container and disk image files an0712 detects extraction or mounting of container archive files e g iso vhd zip that originated from the internet but whose contained files lack zone identifier motw tagging correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside smartscreen or protected view references microsoft 2020 august 31 zone identifier stream name retrieved february 22 2021 beek c 2020 december 3 investigating the use of vhd files by cybercriminals retrieved november 17 2024 hegt s 2020 march 30 mark of the web from a red team s perspective retrieved february 22 2021 kennedy j 2020 december 9 a zebra in gopher s clothing russian apt uses covid 19 lures to deliver zebrocy retrieved february 22 2021 financial security institute 2020 february 28 profiling of ta505 threat group that continues to attack the financial sector retrieved july 14 2022 eset 2022 february threat report t3 2021 retrieved february 10 2022 seongsu park 2022 december 27 bluenoroff introduces new methods bypassing motw retrieved february 6 2024 kenefick i et al 2022 october 12 black basta ransomware gang infiltrates networks via qakbot brute ratel and cobalt strike retrieved february 6 2023 trend micro 2019 august 27 ta505 variety in use of servhelper and flawedammyy retrieved february 22 2021 wdormann 2019 august 29 disable windows explorer file associations for disc image mount retrieved april 16 2022 dormann w 2019 september 4 the dangers of vhd and vhdx files retrieved march 16 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|