For the complete documentation index, see llms.txt. This page is also available as Markdown.

Common third-party software name masquerading

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

EDR Windows Disguised Processes

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Informational

Description

An attacker might leverage common third-party software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a common third-party software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

Variations

Common third-party software name masquerading which was downloaded from an unexpected source

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Low

Description

An attacker might leverage common third-party software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a common third-party software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

Common third-party software name masquerading with uncommon characteristics by actor with uncommon characteristics

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading (T1036)

Severity

Low

Description

An attacker might leverage common third-party software image names to run malicious processes without being caught.

Attacker's Goals

An attacker is attempting to masquerade as a common third-party software image to execute malicious code.

Investigative actions

  • Investigate the executed process image and check if it is malicious.

  • Investigate the actor process that executed the process and check if it is malicious.

Was this helpful?