For the complete documentation index, see llms.txt. This page is also available as Markdown.

A process is masquerading as a common Microsoft product

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

EDR Windows Disguised Processes

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Informational

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

Variations

An unsigned actor executed masqueraded process which was downloaded from unexpected source

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

High

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

An unsigned and rare actor executing masqueraded process with uncommon characteristics

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

High

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

A process that was executed by remote causality actor is masquerading as a common Microsoft product

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Medium

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

A process is masquerading as a common Microsoft Lolbin

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Low

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

A process running from a commonly abused directory is masquerading as a common Microsoft product

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Low

Description

An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

Was this helpful?