Esc
HTML Smuggling - T1027.006
(ATT&CK® Technique)
Definition
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. HTML documents can store large binary objects known as JavaScript Blobs (immutable data that represents raw bytes) that can later be constructed into file-like objects. Data may also be stored in Data URLs, which enable embedding media type or MIME files inline of HTML documents. HTML5 also introduced a download attribute that may be used to initiate file downloads.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.