{"id":"T1036.011","name":"Overwrite Process Arguments","url":"https://attack.mitre.org/techniques/T1036/011","tactics":["stealth"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0164","stix_id":"x-mitre-detection-strategy--8f268381-938f-454e-8d19-f266b69958ea","name":"Detection Strategy for Overwritten Process Arguments Masquerading","url":"https://attack.mitre.org/detectionstrategies/DET0164","analytics":[{"id":"AN0466","stix_id":"x-mitre-analytic--10d8886b-6cf6-45af-b187-04541e2ffaa4","name":"Analytic 0466","description":"Detects adversary behavior where the command-line arguments of a running process are overwritten in memory to spoof the process name, typically replacing it with a benign or misleading string. The detection correlates unexpected null byte sequences, discrepancies between `/proc/<pid>/cmdline` and process ancestry, and suspicious memory writes shortly after process start.","url":"https://attack.mitre.org/detectionstrategies/DET0164#AN0466","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve, prctl, or ptrace activity affecting process memory or command-line arguments","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"auditd-syscall"},{"name":"ebpf:tracepoints","channel":"Runtime memory overwrite of argv[] memory region","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"ebpf-tracepoints"}],"mutable_elements":[{"field":"TimeWindow","description":"Time threshold after process creation during which argv memory manipulation is expected to be rare; anomalies occurring outside this window may be more suspicious."},{"field":"AllowedArgvMismatchPatterns","description":"List of known legitimate processes where argv[0] mismatch is expected due to application logic or packaging quirks."},{"field":"ParentExecutableTrustList","description":"Trusted parent binaries allowed to spawn processes with altered command-line names."}],"live":true,"detection_strategies":["DET0164"],"techniques":["T1036.011"]}],"live":true,"version":"1.0","techniques":["T1036.011"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}