Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕ technique: T1036 ✕
Download CSV Show ATT&CK heatmapA process is masquerading as a common Microsoft product Informational 5 variations
An attacker might leverage common Microsoft software image names to run malicious processes without being caught.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Masquerading (T1036)Required data: XDR AgentDetector tags: EDR Windows Disguised ProcessesAttacker's goals: An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.Investigative actions: Investigate the executed process image and check if it is malicious. Investigate the actor process that executed the process and check if it is malicious.Variations
An unsigned actor executed masqueraded process which was downloaded from unexpected source
High overridden
An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden
An unsigned and rare actor executing masqueraded process with uncommon characteristics
High overridden
An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden
A process that was executed by remote causality actor is masquerading as a common Microsoft product
Medium overridden
An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden
A process is masquerading as a common Microsoft Lolbin
Low overridden
An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden
A process running from a commonly abused directory is masquerading as a common Microsoft product
Low overridden
An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden