Common third-party software name masquerading
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows Disguised Processes
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036)
Severity
Informational
Description
An attacker might leverage common third-party software image names to run malicious processes without being caught.
Attacker's Goals
An attacker is attempting to masquerade as a common third-party software image to execute malicious code.
Investigative actions
Investigate the executed process image and check if it is malicious.
Investigate the actor process that executed the process and check if it is malicious.
Variations
PreviousCommand running with COMSPEC in the command line argument
NextCommonly abused AutoIT script connects to an external domain
Was this helpful?
