Analytics BIOC
Informational
✕
A process is masquerading as a common Microsoft product
An attacker might leverage common Microsoft software image names to run malicious processes without being caught.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Detector tags: EDR Windows Disguised Processes
Attacker's goals:
An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.
Investigative actions:
Investigate the executed process image and check if it is malicious. Investigate the actor process that executed the process and check if it is malicious.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
5 variations:
- An unsigned actor executed masqueraded process which was downloaded from unexpected source High (parent: Informational)
- An unsigned and rare actor executing masqueraded process with uncommon characteristics High (parent: Informational)
- A process that was executed by remote causality actor is masquerading as a common Microsoft product Medium (parent: Informational)
- A process is masquerading as a common Microsoft Lolbin Low (parent: Informational)
- A process running from a commonly abused directory is masquerading as a common Microsoft product Low (parent: Informational)