Execution of masqueraded third-party utility
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows Disguised Processes
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036), Masquerading: Rename Legitimate Utilities (T1036.003)
Severity
Informational
Description
An attacker may be trying to avoid detection of third-party utility execution by renaming it.
Attacker's Goals
Detection avoidance via file masquerading.
Investigative actions
Check the process origin or whether it comes with any packages the user has used.
Variations
Was this helpful?
