Mark-of-the-Web Bypass
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named <code>Zone.Identifier</code> with a specific value known as the MOTW.(Citation: Microsoft Zone.Identifier 2020) Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Pro...
BY SOURCE
PROCEDURES (8)
Auto-extracted: 2 detections for container
Auto-extracted: 2 detections for privilege
Auto-extracted: 2 detections for general monitoring
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for download
Auto-extracted: 1 detections for event log
Auto-extracted: 1 detections for download
Auto-extracted: 1 detections for persist