Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/TA0005
MITRE ATT&CK Tactic

Stealth (TA0005)

ShareXLinkedInRedditHN

The adversary is trying to hide and conceal their actions, appearing as normal behavior. Stealth consists of techniques that reduce the likelihood of detection by blending in with legitimate activity or minimizing observable signals. These techniques are characterized by concealment behaviors, such as avoiding, obfuscating, or mimicking normal operations, without modifying security controls or compromising collection and monitoring feeds. The goal is to remain indistinguishable from benign activity while leaving defensive systems intact.

Techniques (30)

T1006Direct Volume AccessT1014RootkitT1027Obfuscated Files or InformationT1036MasqueradingT1055Process InjectionT1070Indicator RemovalT1078Valid AccountsT1127Trusted Developer Utilities Proxy ExecutionT1134Access Token ManipulationT1140Deobfuscate/Decode Files or InformationT1197BITS JobsT1202Indirect Command ExecutionT1205Traffic SignalingT1211Exploitation for StealthT1216System Script Proxy ExecutionT1218System Binary Proxy ExecutionT1220XSL Script ProcessingT1221Template InjectionT1480Execution GuardrailsT1497Virtualization/Sandbox EvasionT1535Unused/Unsupported Cloud RegionsT1542Pre-OS BootT1564Hide ArtifactsT1574Hijack Execution FlowT1612Build Image on HostT1620Reflective Code LoadingT1622Debugger EvasionT1678Delay ExecutionT1679Selective ExclusionT1684Social Engineering

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. Source: TA0005on MITRE ATT&CK.