Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF008.005
- Created: 02nd August 2026
- Updated: 02nd August 2026
- Contributor: The ITM Team
Document Steganography
A subject conceals data within a business document by using content, objects, fields, formatting, or internal structures that are not visible during ordinary viewing.
The carrier may be a word-processing document, spreadsheet, presentation, Portable Document Format file, or another document type routinely used by the organization. The document may open and display expected content while containing hidden text, files, archives, scripts, worksheets, comments, embedded objects, metadata, or other concealed material.
Methods may include white text on a white background, extremely small font sizes, content positioned outside the visible page, hidden spreadsheet rows or worksheets, concealed presentation objects, embedded files, unused form fields, custom metadata, document layers, or internal package relationships.