1200KM / detection
T1036.005 Match Legitimate Resource Name or Location — Detection Rules
Detection workspace for T1036.005 Match Legitimate Resource Name or Location: 14 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Creation Of Pod In System Namespace · test · medium · {"category":"application","product":"kubernetes","service":"audit"}
- Flash Player Update from Suspicious Location · test · high · {"category":"proxy"}
- Files With System DLL Name In Unsuspected Locations · test · medium · {"category":"file_event","product":"windows"}
- Files With System Process Name In Unsuspected Locations · test · medium · {"category":"file_event","product":"windows"}
- Suspicious Files in Default GPO Folder · test · medium · {"product":"windows","category":"file_event"}
- Unsigned .node File Loaded · experimental · medium · {"category":"image_load","product":"windows"}
- Potential MsiExec Masquerading · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Scheduled Task Creation via Masqueraded XML File · test · medium · {"product":"windows","category":"process_creation"}
- Scheduled Task Creation Masquerading as System Processes · experimental · high · {"category":"process_creation","product":"windows"}
- Windows Processes Suspicious Parent Directory · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Process Masquerading As SvcHost.EXE · test · high · {"category":"process_creation","product":"windows"}
- Uncommon Svchost Command Line Parameter · experimental · high · {"category":"process_creation","product":"windows"}
- Uncommon Svchost Parent Process · test · medium · {"category":"process_creation","product":"windows"}
- Potential Binary Impersonating Sysinternals Tools · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0347 Detection Strategy for Masquerading via Legitimate Resource Name or Location
AN0983 Analytic 0983
Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns.
AN0984 Analytic 0984
Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times.
AN0985 Analytic 0985
Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin.
AN0986 Analytic 0986
Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments.
AN0987 Analytic 0987
Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Carbanak · G0008
- Turla · G0010
- Darkhotel · G0012
- APT29 · G0016
- admin@338 · G0018
- Naikon · G0019
- Lazarus Group · G0032
- Poseidon Group · G0033
- Sandworm Team · G0034
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Sowbug · G0054
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- APT-C-36 · G0099
- Rocke · G0106
- Whitefly · G0107
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- Sidewinder · G0121
- Mustang Panda · G0129
- Transparent Tribe · G0134
- BackdoorDiplomacy · G0135
- Ferocious Kitten · G0137
- TeamTNT · G0139
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- SideCopy · G1008
- LuminousMoth · G1014
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- Mustard Tempest · G1020
- ToddyCat · G1022
- APT5 · G1023
- Akira · G1024
- INC Ransom · G1032
- RedCurl · G1039
- APT42 · G1044
- Storm-1811 · G1046
- Velvet Ant · G1047
- VOID MANTICORE · G1055
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.