T1036 Masquerading — ATT&CK Technique
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
Detection coverage (50)
- Suspicious Computer Account Name Change CVE-2021-42287 high
- Potentially Suspicious Execution From Tmp Folder medium
- CodePage Modification Via MODE.COM low
- Interactive Bash Suspicious Children medium
- PUA - Potential PE Metadata Tamper Using Rcedit medium
- New or Renamed User Account with '$' Character medium
- Password Protected ZIP File Opened (Suspicious Filenames) high
- Windows Binaries Write Suspicious Extensions high
- Potential Homoglyph Attack Using Lookalike Characters in Filename medium
- Suspicious Calculator Usage high
- Suspicious CodePage Switch Via CHCP medium
- CreateDump Process Dump high
- DumpMinitool Execution medium
- Explorer Process Tree Break medium
- Suspicious DumpMinitool Execution high
- Findstr Launching .lnk File medium
- Forfiles.EXE Child Process Masquerading high
- HackTool - XORDump Execution high
- Potential Fake Instance Of Hxtsr.EXE Executed medium
- CodePage Modification Via MODE.COM To Russian Language medium
- Suspicious MSDT Parent Process high
- Renamed CreateDump Utility Execution high
- Renamed ZOHO Dctask64 Execution high
- Renamed Plink Execution high
- Process Memory Dump Via Comsvcs.DLL high
- Suspicious Process Start Locations medium
- Sdiagnhost Calling Suspicious Child Process high
- Potential Command Line Path Traversal Evasion Attempt medium
- Process Execution From A Potentially Suspicious Folder high
- Potential Homoglyph Attack Using Lookalike Characters medium
- Suspicious Process Parents high
- System File Execution Location Anomaly high
- Taskmgr as LOCAL_SYSTEM high
- Potential SysInternals ProcDump Evasion high
- Potential LSASS Process Dump Via Procdump high
- Procdump Execution medium
- New Process Created Via Taskmgr.EXE low
- Potential ReflectDebugger Content Execution Via WerFault.EXE medium
- Suspicious Child Process Of Wermgr.EXE high
- Suspicious Windows Update Agent Empty Cmdline high
- Cisco NVM - Non-Network Binary Making Network Connection
- Executables Or Script Creation In Suspicious Path
- Executables Or Script Creation In Temp Path
- Suspicious writes to windows Recycle Bin
- Windows Bluetooth Service Installed From Uncommon Location
- Windows Debugger Tool Execution
- Windows Masquerading Msdtc Process
- Windows NetSupport RMM DLL Loaded By Uncommon Process
- Windows Suspicious QEMU Execution
- Windows SoftEther VPN Masquerading as Legitimate Binary
Malware using this technique
- Pony
- Raindrop
- AppleSeed
- Saint Bot
- XCSSET
- DarkTortilla
- RedLine Stealer
- GlassWorm
- BeaverTail
- FoggyWeb
- Flagpro
- PowGoop
- Milan
- StrelaStealer
- WindTail
- BoomBox
- TrailBlazer
- UPSTYLE
- Ramsay
- TrickBot
- DarkWatchman
- NotPetya
- NativeZone
- DynoWiper
- RCSession
- WhisperGate
- Dacls
- Ryuk
- EnvyScout
- SombRAT
- RTM
- DarkGate
- Bisonal