Masquerading T1036

Tactic: Stealth

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names.

Events covered

33 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 6Driver loaded
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 29FileExecutableDetected
Security-AuditingEvent ID 4663An attempt was made to access an object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4720A user account was created.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4781The name of an account was changed.
Security-AuditingEvent ID 4799A security-enabled local group membership was enumerated.
Security-AuditingEvent ID 5058Key file operation.
Security-AuditingEvent ID 5059Key migration operation.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5379Credential Manager credentials were read.
Defender-DeviceProcessEventsanyProcess activity
Defender-DeviceProcessEventsProcessCreatedProcess created
ESFexecProcess Execution
ESFopenFile Open
ESFrenameFile Rename
ESFwriteFile Write
Linux-AuditdEvent ID 1309EXECVE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
Windows-DefenderEvent ID 1119ProductName has encountered a critical error when taking action on malware or other potentially unwanted software.
PowerShellEvent ID 400Event ID 400
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 313 rules share fields, values, and exclusions.

Fields filtered most (147 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Image111ends_with 67, starts_with 19, contains 13, wildcard 11, is_not_null 8, eq 7, ne 2, regex_match 2, in 1, is_null 1\cmd.exe, /dev/shm/, \bitsadmin.exe, /boot/, \cscript.exe
process_name83eq 38, regex_match 15, in 12, starts_with 7, wildcard 5, ne 4, contains 3, ends_with 3, cross_field_compare 1, is_not_null 1bash, csh, cp, dash, kworker
CommandLine75contains 49, regex_match 15, ends_with 8, in 6, match 3, eq 2, ne 2, starts_with 2, wildcard 2, is_null 1, length_compare 1 /create , /addfile , /transfer , cp , (?i)(copy-item|copy|xcopy|cp|cpi|robocopy)\s+.+(\x5c(syst...
host.os.type67eq 65, in 2
event.type62eq 60, ne 3start, creation, deletion
EventType57eq 39, in 14, ne 3, starts_with 1exec, start, exec_event, connection_attempted, creation
OriginalFileName57eq 51, contains 2, in 2, wildcard 2, is_not_null 1, ne 1bitsadmin.exe, schtasks.exe, msbuild.exe, msdt.exe, xcopy.exe
EventID37eq 374688, 1, 4103, 4104, 7
ParentImage32ends_with 14, eq 6, is_not_null 6, contains 5, is_null 2, starts_with 2, wildcard 2, cross_field_compare 1, in 1, match 1, ne 1\, \msmpeng.exe, -, ?:\, ?:\programdata\*
parent_process_name29eq 15, is_not_null 5, regex_match 5, in 3, ne 1, starts_with 1, wildcard 1cmd.exe, explorer.exe, powershell.exe, (?i)\s+\x5c, (?i)lsass\.exe
TargetFilename25contains 13, ends_with 9, starts_with 6, wildcard 5, in 4, eq 1, match 1.dll, .exe, .doc., .docx., $recycle.bin
process.args22eq 9, wildcard 7, starts_with 6, in 5, ends_with 2, regex_match 2, is_not_null 1-c, /bin/bash, &, *--as *, *--as-group*
dll.name14eq 11, in 2, wildcard 1winhttp.dll, ws2_32.dll, amsi.dll, bitsproxy.dll, dnsapi.dll
process.args_count13eq 10, ge 2, le 11, 2, 3, 4
process.thread.Ext.call_stack_summary13starts_with 6, eq 3, in 3, contains 1, wildcard 1ntdll.dll, ntdll.dll|, ntdll.dll|archiveint.dll|kernel32.dll|ntdll.dll, ntdll.dll|authfwsnapin.dll|kernel32.dll|ntdll.dll, ntdll.dll|bingmaps.dll|kernel32.dll|ntdll.dll

Top indicator values (6333 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
571078
EventTypeeq
start
18391
EventTypeeq
exec
13576
EventIDeq
4688
12317
EventIDeq
1
11241
EventTypein
exec
8201
EventTypein
exec_event
7149
EventTypein
start
5163
CommandLinecontains
/create
715
CommandLinecontains
/addfile
55
CommandLinecontains
/transfer
55
Imageends_with
\cmd.exe
7130
Imageends_with
\powershell.exe
7179
Imageends_with
\pwsh.exe
7165
Imageends_with
\bitsadmin.exe
629
Imageends_with
\rundll32.exe
694
Imageends_with
\svchost.exe
623
event.categoryeq
process
7142
dll.nameeq
winhttp.dll
616
dll.nameeq
ws2_32.dll
620
process.code_signature.trustedeq
false
6115
process_namein
bash
6202
process_namein
csh
6159
process_namein
dash
6170
process_namein
fish
6163
process_namein
ksh
6163
process_namein
sh
6197
process_namein
tcsh
6156
process_namein
zsh
6196
EventSubTypene
AttackAttempt
57

Exclusions (1698 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.code_signature.trustedeq
true
17
Imagewildcard
?:\program files (x86)\*.exe
7
Imagewildcard
?:\program files\*.exe
7
process_nameeq
rundll32.exe
5
process_nameeq
cmd.exe
4
process_nameeq
powershell.exe
4
Imageends_with
\cmd.exe
4
Imagein
*:\\windows\\system32\\*
4
Imagein
*:\\windows\\syswow64\\*
4
Imagestarts_with
/tmp/newroot/
4
SignatureStatuswildcard
errorCode_endpoint*
4
dll.code_signature.statuswildcard
errorCode_endpoint*
4
parent_process_nameeq
cmd.exe
4
parent_process_nameeq
rundll32.exe
4
parent_process_nameregex_match
^-$
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 97 rules

Elastic 127 rules

Splunk 65 rules

Kusto 24 rules