BIOC Informational

Base64 decoding using the base64 utility

Base64 decoding using the base64 utility with the -d argument provided.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
File Type Obfuscation
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Deobfuscate/Decode Files or Information (T1140)
Indicator:

Process action type = execution AND target process cmd = *-d* AND target process name = base64 Host host os = linux

Preventable: yes