Cross-source coverage
T1036 / ATT&CK
Masquerading
302 rules · 297 families across 9 sources.
25 deprecated hidden · include 18 atomic-IOC hidden · include
From MITRE ATT&CK 19.2
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.
Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.
- Tactics
- Stealth
- Platforms
- Containers · ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:Systemauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogmacos:endpointsecurityfs:fileeventscontainerd:runtimedocker:eventsebpf:syscallsesxi:hostdesxi:shell
How MITRE says to detect it DET0127
Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy
Windows Analytic 0355
Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.
WinEventLog:SysmonEventCode=1WinEventLog:SystemEventCode=7045
Linux Analytic 0356
Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.
auditd:SYSCALLexecvelinux:syslogrenamelinux:osqueryfile_events
macOS Analytic 0357
Adversary creates disguised launch daemons or apps with misleading names and bundle metadata (e.g., Info.plist values inconsistent with binary path or icon). Launch is correlated with user logon or persistence setup.
macos:unifiedlogprocessmacos:endpointsecurityES_EVENT_TYPE_NOTIFY_EXECfs:fileevents/var/log/install.log
Containers Analytic 0358
Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs.
containerd:runtime/var/log/containers/*.logdocker:eventsdocker.events.jsonebpf:syscallsfile_write
ESXi Analytic 0359
Adversary places scripts or binaries with misleading names in /etc/rc.local.d or /var/spool/cron, or registers services with legitimate-sounding names not present in default ESXi builds.
esxi:hostdregisters services with legitimate-sounding namesesxi:shellscripts or binaries with misleading names
Sub-techniques with coverage
Counted in the 302 above — a rule tagged a sub-technique covers this technique too.
- T1036.005 Match Legitimate Resource Name or Location 60
- T1036.003 Rename Legitimate Utilities 57
- T1036.004 Masquerade Task or Service 16
- T1036.001 Invalid Code Signature 11
- T1036.002 Right-to-Left Override 9
- T1036.009 Break Process Trees 7
- T1036.007 Double File Extension 6
- T1036.008 Masquerade File Type 5
- T1036.006 Space after Filename 3
SigmaHQ/sigma
92 rules| Detection | Severity | Format |
|---|---|---|
| Exploit for CVE-2015-1641 | Critical | Sigma |
| Greenbug Espionage Group Indicators | Critical | Sigma |
| RedSun - TieringEngineService.exe Detected as EICAR Test File | Critical | Sigma |
| RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir | Critical | Sigma |
| CreateDump Process Dump | High | Sigma |
| File Download Via Bitsadmin To A Suspicious Target Folder | High | Sigma |
| File With Suspicious Extension Downloaded Via Bitsadmin | High | Sigma |
| Forfiles.EXE Child Process Masquerading | High | Sigma |
| HackTool - XORDump Execution | High | Sigma |
| Lazarus System Binary Masquerading | High | Sigma |
+ 82 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
67 rules| Detection | Severity | Format |
|---|---|---|
| Agent Spoofing - Multiple Hosts Using Same Agent | High | Elastic TOML |
| Binary Executed from Shared Memory Directory | High | Elastic TOML |
| Conhost Spawned By Suspicious Parent Process | High | Elastic TOML |
| Executable Masquerading as Kernel Process | High | Elastic TOML |
| Machine Learning Detected a Suspicious Windows Event with a High Malicious Probability Score | High | Elastic TOML |
| Potential Credential Access via Renamed COM+ Services DLL | High | Elastic TOML |
| Potential CVE-2025-33053 Exploitation | High | Elastic TOML |
| Potential Masquerading as Svchost | High | Elastic TOML |
| Potential Masquerading as System32 DLL | High | Elastic TOML |
| Potential Microsoft Office Sandbox Evasion | High | Elastic TOML |
+ 57 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
48 rules| Detection | Severity | Format |
|---|---|---|
| API Call from a Process with a Spoofed Parent | Undefined | Elastic TOML |
| Binary Masquerading via Untrusted Path | Undefined | Elastic TOML |
| Decoy file Open via Preview App | Undefined | Elastic TOML |
| Evasion via File Name Masquerading | Undefined | Elastic TOML |
| Execution from Suspicious Directory | Undefined | Elastic TOML |
| Execution of Non-Executable File via Shell | Undefined | Elastic TOML |
| Execution via Suspicious JavaScript Updates | Undefined | Elastic TOML |
| Image Load via Synthetic Stack Spoofing | Undefined | Elastic TOML |
| Library Loaded From a Potentially Altered Call Stack | Undefined | Elastic TOML |
| Library Loaded from a Spoofed Call Stack | Undefined | Elastic TOML |
+ 38 more from elastic/protections-artifacts → showing the 10 highest-severity
splunk/security_content
37 rules| Detection | Severity | Format |
|---|---|---|
| Attacker Tools On Endpoint | Undefined | SPL |
| Cisco NVM - Non-Network Binary Making Network Connection | Undefined | SPL |
| Detect RTLO In File Name | Undefined | SPL |
| Detect RTLO In Process | Undefined | SPL |
| Email Attachments With Lots Of Spaces | Undefined | SPL |
| Executables Or Script Creation In Suspicious Path | Undefined | SPL |
| Executables Or Script Creation In Temp Path | Undefined | SPL |
| Execution of File with Multiple Extensions | Undefined | SPL |
| Linux Kworker Process In Writable Process Path | Undefined | SPL |
| Linux Possible System Binary Backdoor | Undefined | SPL |
+ 27 more from splunk/security_content → showing the 10 highest-severity
socfortress/Wazuh-Rules
32 rules · 29 families| Detection | Severity | Format |
|---|---|---|
| AlienVault OTX -Indicator(s) Found | High | Wazuh XML |
| Copying system shell to /tmp with new name — potential masquerading (T1036.003) | High | Wazuh XML |
| Execution from a suspicious '...' directory (Masquerading - T1036.005) | High | Wazuh XML |
| Masquerading as Linux Crond Process. 2 variants | High | Wazuh XML |
| Masquerading as Linux Crond Process. 2 variants | High | Wazuh XML |
| Masquerading via bind mount of /proc (T1036.004) | High | Wazuh XML |
| Process name masquerading via prctl - renamed to 'totally_legit' (T1036.004) | High | Wazuh XML |
| Suspicious shell launched from a masquerading '...' directory (T1036.005) | High | Wazuh XML |
| Sysmon - Event 12: RegistryEvent (Object create and delete) by · Service Registry Key Creation (T1036.004) | High | Wazuh XML |
| Sysmon - Event 13: RegistryEvent (Value Set) by · Masqueraded Service Description Written (T1036.004) | High | Wazuh XML |
+ 22 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Emerging Threats Open
12 rules · 11 families| Detection | Severity | Format |
|---|---|---|
| ET HUNTING ConnectWise ScreenConnect Revoked Code Signing Certificate M1 2 variants | Medium | Suricata |
| ET HUNTING ConnectWise ScreenConnect Revoked Code Signing Certificate M2 2 variants | Medium | Suricata |
| ET HUNTING Automox RMM Installer Downloaded From 3rd Party | Informational | Suricata |
| ET HUNTING Double Extension EXE File Downloaded from Discord (Request) | Informational | Suricata |
| ET HUNTING Double Extension PIF File Downloaded from Discord (Request) | Informational | Suricata |
| ET HUNTING Double Extension VBS File Downloaded from Discord (Request) | Informational | Suricata |
| ET HUNTING Double Extension ZIP File Downloaded from Discord (Request) | Informational | Suricata |
| ET HUNTING Empty Location Header from CloudFlare Server 2024-12-05 | Informational | Suricata |
| ET HUNTING LuminousStealer Legitimate Traffic Impersonation | Informational | Suricata |
| ET HUNTING Redirect to stockx.com | Informational | Suricata |
+ 2 more from Emerging Threats Open → showing the 10 highest-severity
Wazuh Core Ruleset
12 rules+ 2 more from Wazuh Core Ruleset → showing the 10 highest-severity
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Potential re-named sdelete usage (ASIM Version) | Low | KQL |
chainguard-dev/osquery-defense-kit
1 rule| Detection | Severity | Format |
|---|---|---|
| Processes that have an unrelated name in the process tree than the program on disk. | Undefined | osquery SQL |