MITRE ATT&CK CoA - T1027 - Obfuscated Files or Information
This playbook Remediates the Obfuscated Files or Information technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1027: Obfuscated Files or Information Kill Chain phases: - Defense Evasion MITRE ATT&CK Description: Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 10 tasks · 4 inputs · 1 output
Details
| ID | MITRE ATT&CK CoA - T1027 - Obfuscated Files or Information |
|---|---|
| From Version | 6.5.0 |
| Tasks | 10 |
README
This playbook Remediates the Obfuscated Files or Information technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1027: Obfuscated Files or Information
Kill Chain phases:
- Defense Evasion
MITRE ATT&CK Description:
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- PAN-OS - Enforce WildFire Best Practices Profile
Integrations
This playbook does not use any integrations.
Scripts
- Set
- SetGridField
- IsIntegrationAvailable
Commands
This playbook does not use any commands.
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| template | Template name to enforce WildFire best practices profile. | Optional | |
| pre_post | Rules location. Can be ‘pre-rulebase’ or ‘post-rulebase’. Mandatory for Panorama instances. | Optional | |
| device-group | The device group for which to return addresses (Panorama instances). | Optional | |
| tag | Tag for which to filter the results. | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The technique handled in this playbook | unknown |
Playbook Image

Inputs
template— Template name to enforce WildFire best practices profile.pre_post— Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances.device-group— The device group for which to return addresses (Panorama instances).tag— Tag for which to filter the results.
Outputs
Handled.Techniques— The technique handled in this playbook
Flowchart
description: "This playbook Remediates the Obfuscated Files or Information technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1027: Obfuscated Files or Information\n\nKill Chain phases:\n- Defense Evasion\n\nMITRE ATT&CK Description:\n\nAdversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input." id: MITRE ATT&CK CoA - T1027 - Obfuscated Files or Information inputs: - description: Template name to enforce WildFire best practices profile. key: template playbookInputQuery: required: false value: {} - description: Rules location. Can be 'pre-rulebase' or 'post-rulebase'. Mandatory for Panorama instances. key: pre_post playbookInputQuery: required: false value: {} - description: The device group for which to return addresses (Panorama instances). key: device-group playbookInputQuery: required: false value: {} - description: Tag for which to filter the results. key: tag playbookInputQuery: required: false value: {} name: MITRE ATT&CK CoA - T1027 - Obfuscated Files or Information outputs: - contextPath: Handled.Techniques description: The technique handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "5" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 05d9bab4-ce6a-4f9c-89f9-c4b78014c669 iscommand: false name: "" version: -1 description: '' taskid: 05d9bab4-ce6a-4f9c-89f9-c4b78014c669 timertriggers: [] type: start view: |- { "position": { "x": 50, "y": 40 } } "2": id: "2" ignoreworker: false nexttasks: '#none#': - "8" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: Enable Anti-Exploit and Anti-Malware Protection in Cortex XDR. id: eae0fdce-3f5e-43c4-88d3-1f067656476d iscommand: false name: Manual - Enable XDR Anti-Exploit and Anti-Malware Protection type: regular version: -1 taskid: eae0fdce-3f5e-43c4-88d3-1f067656476d timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 1010 } } "3": id: "3" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: f50eccf6-d92c-42d0-8d74-3870ba4f0203 iscommand: false name: Done type: title version: -1 description: '' taskid: f50eccf6-d92c-42d0-8d74-3870ba4f0203 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 1560 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "6" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 6f98fade-a477-4e83-8b3c-985575371137 iscommand: false name: Forward Files for WildFire Analysis type: title version: -1 description: '' taskid: 6f98fade-a477-4e83-8b3c-985575371137 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 195 } } "6": id: "6" ignoreworker: false loop: exitCondition: "" iscommand: false max: 100 wait: 1 nexttasks: '#none#': - "7" note: false quietmode: 0 scriptarguments: ApplyToRule: complex: root: inputs.ApplyToRule device-group: complex: root: inputs.device-group pre-post-rulebase: complex: root: inputs.pre_post rule_name: complex: root: inputs.rule_name tag: complex: root: inputs.tag template: complex: root: inputs.template separatecontext: true skipunavailable: false task: brand: "" id: 1259b4bc-a02b-451b-8929-58d599d5abb6 iscommand: false name: PAN-OS - Enforce WildFire Best Practices Profile playbookId: PAN-OS - Enforce WildFire Best Practices Profile type: playbook version: -1 description: '' taskid: 1259b4bc-a02b-451b-8929-58d599d5abb6 timertriggers: [] type: playbook view: |- { "position": { "x": 50, "y": 340 } } "7": id: "7" ignoreworker: false nexttasks: '#none#': - "9" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 779359f7-4a45-486b-82fa-f847fdc77ec7 iscommand: false name: Cortex XDR type: title version: -1 description: '' taskid: 779359f7-4a45-486b-82fa-f847fdc77ec7 timertriggers: [] type: title view: |- { "position": { "x": 50, "y": 515 } } "8": id: "8" ignoreworker: false nexttasks: '#none#': - "11" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: T1027 separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: 293282c4-6118-45fe-8ff8-8f594acbdbe6 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: 293282c4-6118-45fe-8ff8-8f594acbdbe6 timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 1195 } } "9": id: "9" ignoreworker: false nexttasks: '#default#': - "10" "yes": - "2" note: false quietmode: 0 scriptarguments: brandname: simple: Cortex XDR - IR separatecontext: false skipunavailable: false task: brand: "" description: Returns 'yes' if integration brand is available. Otherwise returns 'no' id: c9064b6e-9ff7-45e8-8f76-ebdd299b5eaf iscommand: false name: Is Cortex XDR integration Enabled? script: IsIntegrationAvailable type: condition version: -1 taskid: c9064b6e-9ff7-45e8-8f76-ebdd299b5eaf timertriggers: [] type: condition view: |- { "position": { "x": 50, "y": 670 } } "10": id: "10" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: | Enable the Cortex XDR integration to follow this CoA. If needed - please contact your Palo Alto Networks account manager for future guidance and assistance. id: 98ba9834-cdbb-4f62-885c-da6fcd6ed8e6 iscommand: false name: Manual - Enable Cortex XDR integration type: regular version: -1 taskid: 98ba9834-cdbb-4f62-885c-da6fcd6ed8e6 timertriggers: [] type: regular view: |- { "position": { "x": 360, "y": 840 } } "11": continueonerror: true id: "11" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: 8d5c9fef-201f-4294-8446-ad1265bcbf1a iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: 8d5c9fef-201f-4294-8446-ad1265bcbf1a timertriggers: [] type: regular view: |- { "position": { "x": 50, "y": 1370 } } version: -1 view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 1585, "width": 690, "x": 50, "y": 40 } } } tests: - No tests (auto formatted) fromversion: 6.5.0