WinDefAVEmu_goatfiles

Goat files inside Defender AV Emulator's file system. Often used in PE malware as an evasion technique to evade executing in Windows Defender's AV Emulator.


Technique Identifier

U1348

Evasion Categories

Detection Rules

Contributor


Created

August 19, 2024

Last Revised

March 24, 2026