T1036.005 Match Legitimate Resource Name or Location
Subtécnica de T1036 Masquerading
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- Exploit for CVE-2015-1641criticalstable · windows
- Greenbug Espionage Group Indicatorscriticaltest · windows
- RedSun - TieringEngineService.exe Detected as EICAR Test Filecriticalexperimental · windows
- RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dircriticalexperimental · windows
- Flash Player Update from Suspicious Locationhightest · proxy
- Lazarus System Binary Masqueradinghightest · windows
- Potential MsiExec Masqueradinghightest · windows
- Small Sieve Malware File Indicator Creationhightest · windows
- Suspicious Process Masquerading As SvcHost.EXEhightest · windows
- RedSun - Conhost.exe Spawned by TieringEngineService.exehighexperimental · windows
- Scheduled Task Creation Masquerading as System Processeshighexperimental · windows
- Uncommon Svchost Command Line Parameterhighexperimental · windows
- Creation Of Pod In System Namespacemediumtest · kubernetes
- Files With System DLL Name In Unsuspected Locationsmediumtest · windows
- Files With System Process Name In Unsuspected Locationsmediumtest · windows
- Potential Binary Impersonating Sysinternals Toolsmediumtest · windows
- Suspicious Files in Default GPO Foldermediumtest · windows
- Suspicious Scheduled Task Creation via Masqueraded XML Filemediumtest · windows
- Uncommon Svchost Parent Processmediumtest · windows
- Unsigned .node File Loadedmediumexperimental · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.