Execution of renamed lolbin
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows Disguised Processes
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036), Masquerading: Rename Legitimate Utilities (T1036.003)
Severity
Informational
Description
An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin.
Attacker's Goals
Detection avoidance via file rename.
Investigative actions
Check the lolbin's origin or whether it comes with any packages the user has used.
Variations
PreviousExecution of masqueraded third-party utility
NextExternal email display name impersonation of internal personnel
Was this helpful?
