1200KM / simulation
T1036.003 Rename Legitimate Utilities — Attack Simulation
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename…
Technique description
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Masquerading - wscript.exe running as svchost.exe
Procedure 24136435-c91a-4ede-9da1-8b284a1c1a23; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading - cscript.exe running as notepad.exe
Procedure 3a2a578b-0a01-46e4-92e3-62e2859b42f0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading as Windows LSASS process
Procedure 5ba5a3d1-cf3c-4499-968a-a93155d1f717; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Malicious process Masquerading as LSM.exe
Procedure 83810c46-f45e-4485-9ab6-8ed0e9e6ed7f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading as FreeBSD or Linux crond process.
Procedure a315bfff-7a98-403b-b442-2ea1b255e556; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading - powershell.exe running as taskhostw.exe
Procedure ac9d0fc3-8aa8-4ab5-b11f-682cd63b40aa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading - non-windows exe running as windows exe
Procedure bc15c13f-d121-4b1f-8c7d-28d95854d086; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerading - windows exe running as different windows exe
Procedure c3d24a39-2bfe-4c6a-b064-90cd73896cb0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.