Threadlinqs IntelligenceStart free

ATT&CK techniqueStealth (formerly Defense Evasion)

T1564 Hide Artifacts

Stealth (formerly Defense Evasion)Enterprise

As of 2026-10-05, T1564 (Hide Artifacts) appears in 174 tracked threats, first reported 2021-11-25 and most recently 2026-09-25, with linked actors including Contagious Interview, APT38, Lazarus Group; it most often appears alongside T1059 (Command and Scripting Interpreter).

Tracked threats
17445 critical, 120 high, 9 medium
First seen
2021-11-25
Last seen
2026-09-25
Threat actors
92In the threats using it
Detection rules
124Blue tier and above

Data as of:

Activity timeline

T1564 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-06 with 56 reports, and 173 of the 174 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1564 Hide Artifacts is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 174 of 2623 tracked threats (6.6%) to it; by severity that is 45 critical, 120 high, 9 medium.

Threats that use T1564 most often also use T1059 Command and Scripting Interpreter (126 threats), T1027 Obfuscated Files or Information (124 threats), T1071 Application Layer Protocol (112 threats), T1082 System Information Discovery (111 threats), T1036 Masquerading (109 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

92 tracked threat actors appear in the threats that use T1564; the most frequent are Contagious Interview (6), APT38 (4), Lazarus Group (4), Stardust Chollima (4), TeamPCP (4).

Mitigations

MITRE ATT&CK lists 4 mitigations for T1564.

Data sources

Telemetry that can reveal T1564, per MITRE ATT&CK.

  • Application Log — Application Log Content
  • Command — Command Execution
  • File — File Creation, File Metadata, File Modification
  • Firmware — Firmware Modification
  • Process — OS API Execution, Process Creation
  • Script — Script Execution
  • Service — Service Creation
  • User Account — User Account Creation, User Account Metadata
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 174 tracked threats that use T1564.

Detection coverage

Threadlinqs maintains 124 detection rules mapped to T1564 (SPL 32, KQL 45, Sigma 47). Rule content is available to Blue tier accounts and above; this page shows counts only.

124 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1564.001 Hidden Files and Directories — 84 tracked threats
  • T1564.002 Hidden Users — 1 tracked threat
  • T1564.003 Hidden Window — 37 tracked threats
  • T1564.004 NTFS File Attributes — 11 tracked threats
  • T1564.005 Hidden File System — 0 tracked threats
  • T1564.006 Run Virtual Instance — 3 tracked threats
  • T1564.007 VBA Stomping — 0 tracked threats
  • T1564.008 Email Hiding Rules — 11 tracked threats
  • T1564.009 Resource Forking — 0 tracked threats
  • T1564.010 Process Argument Spoofing — 3 tracked threats
  • T1564.011 Ignore Process Interrupts — 1 tracked threat
  • T1564.012 File/Path Exclusions — 2 tracked threats
  • T1564.013 Bind Mounts — 1 tracked threat
  • T1564.014 Extended Attributes — 0 tracked threats