IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: What does the TTP type FILELESS mean?

Endpoint Standard: What does the TTP type FILELESS mean?

Environment

  • CB Cloud: All Versions
  • Endpoint Standard: All Versions 

Question

What does FILELESS TTP mean?

Answer

The Fileless TTP is something that can apply to most script interpreters, such as Python, Powershell, Ruby, etc. Due to the wide range of interpreters, the details are necessarily different for each, but essentially we look for indicators of a command line execution of arbitrary input. For Powershell, -command is one such indicator.

Additional Notes

Fileless behavior can be an indicator of compromise but also occurs in perfectly legitimate applications. If it is an on disk script subsequently performing fileless activity, this model is also common to malicious code. The TTP: FILELESS is appropriate in this case even though the script is not itself malicious.

Related Content


Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎08-18-2020
Views:
849
Contributors