Analytics BIOC Informational

Common third-party software name masquerading

An attacker might leverage common third-party software image names to run malicious processes without being caught.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Detector tags: EDR Windows Disguised Processes
Attacker's goals:

An attacker is attempting to masquerade as a common third-party software image to execute malicious code.

Investigative actions:

Investigate the executed process image and check if it is malicious. Investigate the actor process that executed the process and check if it is malicious.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Common third-party software name masquerading which was downloaded from an unexpected source Low (parent: Informational)
  • Common third-party software name masquerading with uncommon characteristics by actor with uncommon characteristics Low (parent: Informational)