T1036 Masquerading
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Exploit for CVE-2015-1641criticalstable · windows
- Greenbug Espionage Group Indicatorscriticaltest · windows
- RedSun - TieringEngineService.exe Detected as EICAR Test Filecriticalexperimental · windows
- RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dircriticalexperimental · windows
- Potential LSASS Process Dump Via Procdumphighstable · windows
- CreateDump Process Dumphightest · windows
- File Download Via Bitsadmin To A Suspicious Target Folderhightest · windows
- File With Suspicious Extension Downloaded Via Bitsadminhightest · windows
- Flash Player Update from Suspicious Locationhightest · proxy
- Forfiles.EXE Child Process Masqueradinghightest · windows
- HackTool - XORDump Executionhightest · windows
- LOL-Binary Copied From System Directoryhightest · windows
- Lazarus System Binary Masqueradinghightest · windows
- Operation Wocao Activityhightest · windows
- Operation Wocao Activity - Securityhightest · windows
- Password Protected ZIP File Opened (Suspicious Filenames)hightest · windows
- Potential Defense Evasion Via Rename Of Highly Relevant Binarieshightest · windows
- Potential Defense Evasion Via Right-to-Left Overridehightest · windows
- Potential File Extension Spoofing Using Right-to-Left Overridehightest · windows
- Potential MsiExec Masqueradinghightest · windows
- Potential SysInternals ProcDump Evasionhightest · windows
- Potential WerFault ReflectDebugger Registry Value Abusehightest · windows
- Process Execution From A Potentially Suspicious Folderhightest · windows
- Process Memory Dump Via Comsvcs.DLLhightest · windows
- Ps.exe Renamed SysInternals Toolhightest · windows
Mostrando 25 de 88.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.