1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1036.011 Overwrite Process Arguments — Detection Rules

Detection workspace for T1036.011 Overwrite Process Arguments: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0164 Detection Strategy for Overwritten Process Arguments Masquerading

AN0466 Analytic 0466

Detects adversary behavior where the command-line arguments of a running process are overwritten in memory to spoof the process name, typically replacing it with a benign or misleading string. The detection correlates unexpected null byte sequences, discrepancies between `/proc//cmdline` and process ancestry, and suspicious memory writes shortly after process start.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1036.011 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.