1200KM / simulation
T1036.004 Masquerade Task or Service — Attack Simulation
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of…
Technique description
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Hiding a malicious process with bind mounts
Procedure ad4b73c2-d6e2-4d8b-9868-4c6f55906e01; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Creating W32Time similar named service using sc
Procedure b721c6ef-472c-4263-a0d9-37f1f4ecff66; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- linux rename /proc/pid/comm using prctl
Procedure f0e3aaea-5cd9-4db6-a077-631dd19b27a8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Creating W32Time similar named service using schtasks
Procedure f9f2fe59-96f7-4a7d-ba9f-a9783200d4c9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Carbanak · G0008
- Naikon · G0019
- Lazarus Group · G0032
- FIN6 · G0037
- FIN7 · G0046
- APT32 · G0050
- PROMETHIUM · G0056
- Magic Hound · G0059
- Kimsuky · G0094
- APT41 · G0096
- APT-C-36 · G0099
- Wizard Spider · G0102
- Fox Kitten · G0117
- Higaisa · G0126
- ZIRCONIUM · G0128
- BackdoorDiplomacy · G0135
- Aquatic Panda · G0143
- BITTER · G1002
- FIN13 · G1016
- Winter Vivern · G1035
- UNC3886 · G1048
- Storm-0501 · G1053
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.