If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1564/009 - Hide Artifacts: Resource Forki.

site address: attack.mitre.org/techniques/T1564/009 redirected to: attack.mitre.org/techniques/T1564/009

site title: Hide Artifacts: Resource Forking, Sub-technique T1564.009 - Enterprise MITRE ATT&CK®

Our opinion (on Tuesday 18 August 2026 20:20:48 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

hide, artifacts, resource, forking, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of, 14,

Text of the page (most frequently used words):
t1564 (17), #resource (16), the (11), att (10), all (10), october (9), and (8), 2021 (8), enterprise (7), resources (7), data (7), retrieved (7), fork (7), hide (7), detection (6), macos (6), file (6), are (5), ics (5), mobile (5), none (5), techniques (5), attributes (5), forks (5), with (5), forking (5), mitre (4), sub (4), files (4), extended (4), application (4), version (4), may (4), hidden (4), artifacts (4), 2026 (3), use (3), cti (3), mitigations (3), defenses (3), osx (3), keydnap (3), for (3), 2020 (3), process (3), description (3), name (3), applications (3), bundle (3), location (3), 009 (3), adversaries (3), can (3), corporation (2), domains (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), apple (2), security (2), july (2), malware (2), more (2), than (2), non (2), when (2), execution (2), strategy (2), analytic (2), structure (2), folder (2), evade (2), shlayer (2), icon (2), executable (2), system (2), technique (2), malicious (2), that (2), content (2), code (2), localized (2), placed (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, inc, february, app, overview, marc, etienne, leveille, 2016, new, hungry, credentials, 2017, erika, noerenberg, june, tau, threat, analysis, bundlore, install, phil, stokes, november, resourceful, hides, named, howard, oakley, there, flylib, identifying, tenon, references, unexpected, creation, modification, containing, unusually, large, standard, defender, perspective, contexts, where, they, uncommon, especially, paired, network, activity, com, resourcefork, an1609, det0584, configure, which, leverages, developer, guidance, m1013, mitigation, has, used, compressed, binary, itself, from, terminal, finder, potentially, traditional, scanners, s0402, uses, present, jpeg, text, rather, assigned, operating, s0276, procedure, examples, live, permalink, last, modified, created, ivan, sinyakov, jaron, bradley, jbradley89, contributors, platforms, stealth, tactic, otherwise, stored, directly, execute, attached, specified, offset, moved, then, invoked, also, obfuscated, encrypted, until, abuse, executables, bypass, provides, structured, way, store, such, thumbnail, images, menu, definitions, icons, dialog, boxes, usage, identifiable, displaying, using, commands, have, been, deprecated, replaced, top, level, directory, while, xattr, 014, bind, mounts, 013, path, exclusions, 012, ignore, interrupts, 011, argument, spoofing, 010, email, hiding, rules, 008, vba, stomping, 007, run, virtual, instance, 006, 005, ntfs, 004, window, 003, users, 002, directories, 001, other, home, open, join, mclean, hotel, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
hide artifacts resource forking sub technique t1564 009 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise hide artifacts resource forking hide artifacts resource forking other sub techniques of hide artifacts 14 id name t1564 001 hidden files and directories t1564 002 hidden users t1564 003 hidden window t1564 004 ntfs file attributes t1564 005 hidden file system t1564 006 run virtual instance t1564 007 vba stomping t1564 008 email hiding rules t1564 009 resource forking t1564 010 process argument spoofing t1564 011 ignore process interrupts t1564 012 file path exclusions t1564 013 bind mounts t1564 014 extended attributes adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications a resource fork provides applications a structured way to store resources such as thumbnail images menu definitions icons dialog boxes and code 1 usage of a resource fork is identifiable when displaying a file s extended attributes using ls l or xattr l commands resource forks have been deprecated and replaced with the application bundle structure non localized resources are placed at the top level directory of an application bundle while localized resources are placed in the resources folder 2 3 adversaries can use resource forks to hide malicious data that may otherwise be stored directly in files adversaries can execute content with an attached resource fork at a specified offset that is moved to an executable location then invoked resource fork content may also be obfuscated encrypted until execution 4 5 id t1564 009 sub technique of t1564 ⓘ tactic stealth ⓘ platforms macos contributors ivan sinyakov jaron bradley jbradley89 version 2 0 created 12 october 2021 last modified 12 may 2026 version permalink live version procedure examples id name description s0276 keydnap keydnap uses a resource fork to present a macos jpeg or text file icon rather than the executable s icon assigned by the operating system 6 s0402 osx shlayer osx shlayer has used a resource fork to hide a compressed binary file of itself from the terminal finder and potentially evade traditional scanners 5 4 mitigations id mitigation description m1013 application developer guidance configure applications to use the application bundle structure which leverages the resources folder location 7 detection strategy id name analytic id analytic description det0584 detection strategy for resource forking on macos an1609 unexpected creation or modification of files with com apple resourcefork extended attributes containing unusually large or non standard data defender perspective detection of resource forks in contexts where they are uncommon especially when paired with process execution or network activity references tenon n d retrieved october 12 2021 flylib n d identifying resource and data forks retrieved october 12 2021 howard oakley 2020 october 24 there s more to files than data extended attributes retrieved october 12 2021 phil stokes 2020 november 5 resourceful macos malware hides in named fork retrieved october 12 2021 erika noerenberg 2020 june 29 tau threat analysis bundlore macos mm install macos retrieved october 12 2021 marc etienne m leveille 2016 july 6 new osx keydnap malware is hungry for credentials retrieved july 3 2017 apple inc 2021 february 18 app security overview retrieved october 12 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 61 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-61


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1564/009
X-GitHub-Request-Id 5E80:30BAF3:3B07814:3B6AAEC:6A84BEA0
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Tue, 18 Aug 2026 20:20:48 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290025-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787084449.562869,VS0,VE103
Vary Accept-Encoding
X-Fastly-Request-ID c870a6609a916dce4a1e1db97dcad4b50dffc960
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1564/009/
access-control-allow-origin *
expires Tue, 18 Aug 2026 20:30:48 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id D942:112AD3:56FDED:5B076F:6A84BE9D
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 20:20:48 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630094-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787084449.691643,VS0,VE83
vary Accept-Encoding
x-fastly-request-id 044f5d1acadbb327c030f2f015d846db09f26ce1
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-ce71
expires Tue, 18 Aug 2026 20:30:48 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id C074:7AD6C:577CFE:5B870C:6A84BEA0
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 20:20:48 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630094-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787084449.783283,VS0,VE88
vary Accept-Encoding
x-fastly-request-id e3977db0f0b1bf2cf91b13f185a5893d6617cfd7
content-length 8218

Meta Tags

title="Hide Artifacts: Resource Forking, Sub-technique T1564.009 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size8218
load time (s)0.543483
redirect count2
speed download15134
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"