T1027.011 Fileless Storage

Adversaries may store data in “fileless” formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage include the Windows Registry, event logs, or WMI repository.21

Similar to fileless in-memory behaviors such as Reflective Code Loading and Process Injection, fileless data storage may remain undetected by anti-virus and other endpoint security tools that can only access specific file formats from disk storage.

Adversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of Persistence) and collected data not yet exfiltrated from the victim (e.g., Local Data Staging). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored.

Some forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., %SystemRoot%\System32\Wbem\Repository) or Registry (e.g., %SystemRoot%\System32\Config) physical files.2

Item Value
ID T1027.011
Sub-techniques T1027.001, T1027.002, T1027.003, T1027.004, T1027.005, T1027.006, T1027.007, T1027.008, T1027.009, T1027.010, T1027.011
Tactics TA0005
Platforms Windows
Version 1.0
Created 23 March 2023
Last Modified 04 May 2023

Procedure Examples

ID Name Description
G0050 APT32 APT32‘s backdoor has stored its configuration in a registry key.38
S0631 Chaes Some versions of Chaes stored its instructions (otherwise in a instructions.ini file) in the Registry.18
S0023 CHOPSTICK CHOPSTICK may store RC4 encrypted configuration information in the Windows Registry.3
S0126 ComRAT ComRAT has stored encrypted orchestrator code and payloads in the Registry.87
S0673 DarkWatchman DarkWatchman can store configuration strings, keylogger, and output of components in the Registry.37
S0343 Exaramel for Windows Exaramel for Windows stores the backdoor’s configuration in the Registry in XML format.27
S0666 Gelsemium Gelsemium can store its components in the Registry.9
S0531 Grandoreiro Grandoreiro can store its configuration in the Registry at HKCU\Software\ under frequently changing names including %USERNAME% and ToolTech-RM.24
S0256 Mosquito Mosquito stores configuration values under the Registry key HKCU\Software\Microsoft[dllname].26
S0198 NETWIRE NETWIRE can store its configuration information in the Registry under HKCU:\Software\Netwire.25
C0012 Operation CuckooBees During Operation CuckooBees, the threat actors stroed payloads in Windows CLFS (Common Log File System) transactional logs.41
S0517 Pillowmint Pillowmint has stored a compressed payload in the Registry key HKLM\SOFTWARE\Microsoft\DRM.6
S0501 PipeMon PipeMon has stored its encrypted payload in the Registry under HKLM\SOFTWARE\Microsoft\Print\Components\.34
S0518 PolyglotDuke PolyglotDuke can store encrypted JSON configuration files in the Registry.28
S0650 QakBot QakBot can store its configuration information in a randomly named subkey under HKCU\Software\Microsoft.3231
S0269 QUADAGENT QUADAGENT stores a session identifier unique to the compromised system as well as a pre-shared key used for encrypting and decrypting C2 communications within a Registry key (such as HKCU\Office365DCOMCheck) in the HKCU hive.36
S0662 RCSession RCSession can store its obfuscated configuration file in the Registry under HKLM\SOFTWARE\Plus or HKCU\SOFTWARE\Plus.3029
S0511 RegDuke RegDuke can store its encryption key in the Registry.28
S0496 REvil REvil can save encryption parameters and system information in the Registry.1114131210
S0596 ShadowPad ShadowPad maintains a configuration block and virtual file system in the Registry.54
S0589 Sibot Sibot has installed a second-stage script in the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\sibot registry key.35
S0663 SysUpdate SysUpdate can store its encoded configuration file within Software\Classes\scConfig in either HKEY_LOCAL_MACHINE or HKEY_CURRENT_USER.33
S0665 ThreatNeedle ThreatNeedle can save its configuration data as a RC4-encrypted Registry key under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\GameCon.23
S0668 TinyTurla TinyTurla can save its configuration parameters in the Registry.19
G0010 Turla Turla has used the Registry to store encrypted and encoded payloads.3940
S0263 TYPEFRAME TYPEFRAME can install and store encrypted configuration data under the Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellCompatibility\Applications\laxhost.dll and HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PrintConfigs.20
S0476 Valak Valak has the ability to store information regarding the C2 server and downloads in the Registry key HKCU\Software\ApplicationContainer\Appsw64.171516
S0180 Volgmer Volgmer stores an encoded configuration file in HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Security.2122


ID Mitigation Description
M1047 Audit Consider periodic review of common fileless storage locations (such as the Registry or WMI repository) to potentially identify abnormal and malicious data.


ID Data Source Data Component
DS0024 Windows Registry Windows Registry Key Creation
DS0005 WMI WMI Creation


