BIOC
Informational
✕
Common Mozilla process name missing Mozilla digital certificate
These common Mozilla process names should normally be signed with the Mozilla Corporation digital signature. Naming processes with common names is a common way attackers obfuscate their activities.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- File Type Obfuscation
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Indicator:
Process action type = execution AND target process name = firefox.exe AND process execution signer != *Mozilla Corporation* Host host os = windows
Preventable: yes