kevmap

TechniquesT1036 › AN0356

AN0356 Analytic 0356

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary drops renamed binaries in uncommon directories (e.g., /tmp, /dev/shm) or uses special characters in names (e.g., trailing space, Unicode RLO). Execution or cronjob registration follows shortly after file drop.</p>
Detects
T1036 Masquerading
Part of
DET0127 Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLexecveDC0032 Process Creation
linux:syslogrenameDC0061 File Modification
linux:osqueryfile_eventsDC0059 File Metadata

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
DropLocationPatternDirectories where new binaries are suspicious (e.g., /tmp)
FilenameAnomaliesRegex for Unicode/RLO/space abuse in filenames
ExecutionDelayWindowTime range between file write and execution used for joining

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-26500Veeam Backup & ReplicationMapped
CVE-2022-26501Veeam Backup & ReplicationMapped