Cross-source coverage

T1036 / ATT&CK

Masquerading

327 rules · 322 families across 10 sources.

18 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Renaming abusable system utilities to evade security monitoring is also a form of Masquerading.

Tactics
Stealth
Platforms
Containers · ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:SysmonWinEventLog:Systemauditd:SYSCALLlinux:sysloglinux:osquerymacos:unifiedlogmacos:endpointsecurityfs:fileeventscontainerd:runtimedocker:eventsebpf:syscallsesxi:hostdesxi:shell

How MITRE says to detect it DET0127

Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy

Windows Analytic 0355

Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:System EventCode=7045

Linux Analytic 0356

Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.

  • auditd:SYSCALL execve
  • linux:syslog rename
  • linux:osquery file_events

macOS Analytic 0357

Adversary creates disguised launch daemons or apps with misleading names and bundle metadata (e.g., Info.plist values inconsistent with binary path or icon). Launch is correlated with user logon or persistence setup.

  • macos:unifiedlog process
  • macos:endpointsecurity ES_EVENT_TYPE_NOTIFY_EXEC
  • fs:fileevents /var/log/install.log

Containers Analytic 0358

Adversary uses renamed container images, injects files into containers with misleading names or metadata (e.g., renamed system binaries), and executes them during startup or scheduled jobs.

  • containerd:runtime /var/log/containers/*.log
  • docker:events docker.events.json
  • ebpf:syscalls file_write

ESXi Analytic 0359

Adversary places scripts or binaries with misleading names in /etc/rc.local.d or /var/spool/cron, or registers services with legitimate-sounding names not present in default ESXi builds.

  • esxi:hostd registers services with legitimate-sounding names
  • esxi:shell scripts or binaries with misleading names

Sub-techniques with coverage

Counted in the 327 above — a rule tagged a sub-technique covers this technique too.


SigmaHQ/sigma

92 rules
Detection Severity Format
Exploit for CVE-2015-1641 Critical Sigma
Greenbug Espionage Group Indicators Critical Sigma
RedSun - TieringEngineService.exe Detected as EICAR Test File Critical Sigma
RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir Critical Sigma
CreateDump Process Dump High Sigma
File Download Via Bitsadmin To A Suspicious Target Folder High Sigma
File With Suspicious Extension Downloaded Via Bitsadmin High Sigma
Forfiles.EXE Child Process Masquerading High Sigma
HackTool - XORDump Execution High Sigma
Lazarus System Binary Masquerading High Sigma

+ 82 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

71 rules
Detection Severity Format
Agent Spoofing - Multiple Hosts Using Same Agent High Elastic TOML
Binary Executed from Shared Memory Directory High Elastic TOML
Conhost Spawned By Suspicious Parent Process High Elastic TOML
Deprecated - Agent Spoofing - Mismatched Agent ID High Elastic TOML
Executable Masquerading as Kernel Process High Elastic TOML
Machine Learning Detected a Suspicious Windows Event with a High Malicious Probability Score High Elastic TOML
Potential Credential Access via Renamed COM+ Services DLL High Elastic TOML
Potential CVE-2025-33053 Exploitation High Elastic TOML
Potential Masquerading as Svchost High Elastic TOML
Potential Masquerading as System32 DLL High Elastic TOML

+ 61 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

48 rules
Detection Severity Format
API Call from a Process with a Spoofed Parent Undefined Elastic TOML
Binary Masquerading via Untrusted Path Undefined Elastic TOML
Decoy file Open via Preview App Undefined Elastic TOML
Evasion via File Name Masquerading Undefined Elastic TOML
Execution from Suspicious Directory Undefined Elastic TOML
Execution of Non-Executable File via Shell Undefined Elastic TOML
Execution via Suspicious JavaScript Updates Undefined Elastic TOML
Image Load via Synthetic Stack Spoofing Undefined Elastic TOML
Library Loaded From a Potentially Altered Call Stack Undefined Elastic TOML
Library Loaded from a Spoofed Call Stack Undefined Elastic TOML

+ 38 more from elastic/protections-artifacts → showing the 10 highest-severity

splunk/security_content

37 rules
Detection Severity Format
Attacker Tools On Endpoint Undefined SPL
Cisco NVM - Non-Network Binary Making Network Connection Undefined SPL
Detect RTLO In File Name Undefined SPL
Detect RTLO In Process Undefined SPL
Email Attachments With Lots Of Spaces Undefined SPL
Executables Or Script Creation In Suspicious Path Undefined SPL
Executables Or Script Creation In Temp Path Undefined SPL
Execution of File with Multiple Extensions Undefined SPL
Linux Kworker Process In Writable Process Path Undefined SPL
Linux Possible System Binary Backdoor Undefined SPL

+ 27 more from splunk/security_content → showing the 10 highest-severity

socfortress/Wazuh-Rules

32 rules · 29 families
Detection Severity Format
AlienVault OTX -Indicator(s) Found High Wazuh XML
Copying system shell to /tmp with new name — potential masquerading (T1036.003) High Wazuh XML
Execution from a suspicious '...' directory (Masquerading - T1036.005) High Wazuh XML
Masquerading as Linux Crond Process. 2 variants High Wazuh XML
Masquerading as Linux Crond Process. 2 variants High Wazuh XML
Masquerading via bind mount of /proc (T1036.004) High Wazuh XML
Process name masquerading via prctl - renamed to 'totally_legit' (T1036.004) High Wazuh XML
Suspicious shell launched from a masquerading '...' directory (T1036.005) High Wazuh XML
Sysmon - Event 12: RegistryEvent (Object create and delete) by · Service Registry Key Creation (T1036.004) High Wazuh XML
Sysmon - Event 13: RegistryEvent (Value Set) by · Masqueraded Service Description Written (T1036.004) High Wazuh XML

+ 22 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

chronicle/detection-rules

19 rules
Detection Severity Format
detect_rogue_servicesexe_process Undefined YARA-L
detects_malware_acrord32exe_execution_process Undefined YARA-L
executables_started_in_suspicious_folder Undefined YARA-L
execution_in_nonexecutable_folder Undefined YARA-L
exploit_for_cve20151641 Undefined YARA-L
fireeye_red_team_tool__modified_impacket_smbexec_via_cmdline Undefined YARA-L
fireeye_red_team_tool__modified_impacket_smbexec_via_registry Undefined YARA-L
modification_of_windows_defender_service_settings_sysmon Undefined YARA-L
powershell_base64_encoded_shellcode Undefined YARA-L
psexe_renamed_sysinternals_tool Undefined YARA-L

+ 9 more from chronicle/detection-rules → showing the 10 highest-severity

Emerging Threats Open

14 rules · 13 families
Detection Severity Format
ET DELETED Possible Malicious Attachment With Double Extension Ending In EXE High Suricata
ET HUNTING ConnectWise ScreenConnect Revoked Code Signing Certificate M1 2 variants Medium Suricata
ET HUNTING ConnectWise ScreenConnect Revoked Code Signing Certificate M2 2 variants Medium Suricata
ET HUNTING Automox RMM Installer Downloaded From 3rd Party Informational Suricata
ET HUNTING Double Extension EXE File Downloaded from Discord (Request) Informational Suricata
ET HUNTING Double Extension PIF File Downloaded from Discord (Request) Informational Suricata
ET HUNTING Double Extension VBS File Downloaded from Discord (Request) Informational Suricata
ET HUNTING Double Extension ZIP File Downloaded from Discord (Request) Informational Suricata
ET HUNTING Empty Location Header from CloudFlare Server 2024-12-05 Informational Suricata
ET HUNTING LuminousStealer Legitimate Traffic Impersonation Informational Suricata

+ 4 more from Emerging Threats Open → showing the 10 highest-severity

Wazuh Core Ruleset

12 rules
Detection Severity Format
Executed suspicious process with right to left override character in binary file, possible malicious file masquerading Critical Wazuh XML
Masqueraded CertUtil.exe used to decode binary file Critical Wazuh XML
Masqueraded CertUtil.exe with a different file name. Possible use to decode malware Critical Wazuh XML
Suspicious process (right to left override character) spawned a subprocess Critical Wazuh XML
Executed a renamed copy of wscript.exe High Wazuh XML
An executable created a file in a Windows folder · win.eventdata.image = (?i)(accesschk|calc|hex2dec)\.exe, win.eventdata.targetFilename = (?i)Windows\\\\(SysWOW64|Temp|System32|System) Low Wazuh XML
osquery: : conhost.exe process masquerading detected, path is · osquery.name = conhost.exe_incorrect_path Low Wazuh XML
osquery: : dllhost.exe process masquerading detected, path is · osquery.name = dllhost.exe_incorrect_path Low Wazuh XML
osquery: : lsass.exe process masquerading detected, path is · osquery.name = lsass.exe_incorrect_path Low Wazuh XML
osquery: : services.exe process masquerading detected, the parent process is incorrect · osquery.name = services.exe_incorrect_parent_process Low Wazuh XML

+ 2 more from Wazuh Core Ruleset → showing the 10 highest-severity

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Potential re-named sdelete usage (ASIM Version) Low KQL

chainguard-dev/osquery-defense-kit

1 rule
Detection Severity Format
Processes that have an unrelated name in the process tree than the program on disk. Undefined osquery SQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.