kevmap

TechniquesT1036 › AN0355

AN0355 Analytic 0355

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary renames LOLBINs or deploys binaries with spoofed file names, internal PE metadata, or misleading icons to appear legitimate. File creation is followed by execution or service registration inconsistent with known usage.</p>
Detects
T1036 Masquerading
Part of
DET0127 Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SystemEventCode=7045DC0060 Service Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
OriginalFilenameMismatchCompare executable file name with PE metadata OriginalFilename field
KnownSystemUtilityPathsTune based on expected installation directories for signed binaries
TimeWindowCorrelation window between file creation and service/process execution

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped