Command Obfuscation
Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns within commands and scripts more difficult to signature and analyze. This type of obfuscation can be included within commands executed by delivered payloads (e.g., [Phishing](https://attack.mitre.org/techniques/T1566) and [Drive-by Compromise](https://attack.mitre.org/techniques/T1189)) or interactively via [Command and Scripting Interpreter](https:/...
BY SOURCE
PROCEDURES (19)
Auto-extracted: 4 detections for amsi
Auto-extracted: 4 detections for bypass
Auto-extracted: 2 detections for registry
Auto-extracted: 2 detections for script block
Auto-extracted: 2 detections for obfuscat
Auto-extracted: 2 detections for http
Auto-extracted: 2 detections for token
Auto-extracted: 2 detections for base64
Auto-extracted: 1 detections for token
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for command line monitoring
Auto-extracted: 1 detections for base64
Auto-extracted: 1 detections for script execution monitoring
Auto-extracted: 1 detections for obfuscat
Auto-extracted: 1 detections for obfuscat
Auto-extracted: 1 detections for amsi
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for phish
Auto-extracted: 1 detections for unusual