Skip to content

MITRE ATT&CK sub-technique

T1564.009 — Resource Forking

Last fetched

T1564.009 (Resource Forking) is a MITRE ATT&CK sub-technique tracked in WhisperGraph, serving the Stealth tactic.

Description

Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications. A resource fork provides applications a structured way to store resources such as thumbnail images, menu definitions, icons, dialog boxes, and code.(Citation: macOS Hierarchical File System Overview) Usage of a resource fork is identifiable when displaying a file’s extended attributes, using <code>ls -l@</code> or <code>xattr -l</code> commands. Resource forks have been deprecated and replaced with the application bundle structure. Non-localized resources are placed at the top level directory of an application bundle, while localized resources are placed in the <code>/Resources</code> folder.(Citation: Resource and Data Forks)(Citation: ELC Extended Attributes) Adversaries can use resource forks to hide malicious data that may otherwise be stored directly in files. Adversaries can execute content with an attached resource fork, at a specified offset, that is moved to an executable location then invoked. Resource fork content may also be obfuscated/encrypted until execution.(Citation: sentinellabs resource named fork 2020)(Citation: tau bundlore erika noerenberg 2020)

Tactics

Related techniques

Parent technique: T1564 · Hide Artifacts

Threat actors observed using this technique

No threat actor is recorded using T1564.009 in WhisperGraph.

© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

Related pages

Pivot from T1564.009 into its tactic, related techniques and the actors that use it.

Queries

Resolves the segment to this technique or tactic.


MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS description
Run yourself →

The tactic(s) this technique serves.


MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10
Run yourself →

This id's parent technique, if it is a sub-technique.


MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1
Run yourself →

Sub-techniques of this technique, if any.


MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25
Run yourself →

Threat actors observed using this technique.


MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.