1200KM / simulation
T1036.005 Match Legitimate Resource Name or Location — Attack Simulation
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to…
Technique description
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Masquerading cmd.exe as VEDetector.exe
Procedure 03ae82a6-9fa0-465b-91df-124d8ca5c4e8; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Masquerade as a built-in system executable
Procedure 35eb8d16-9820-4423-a2a1-90c4f5edd9ca; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Execute a process from a directory masquerading as the current parent directory
Procedure 812c3ab8-94b0-4698-a9bf-9420af23ce24; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Carbanak · G0008
- Turla · G0010
- Darkhotel · G0012
- APT29 · G0016
- admin@338 · G0018
- Naikon · G0019
- Lazarus Group · G0032
- Poseidon Group · G0033
- Sandworm Team · G0034
- Patchwork · G0040
- menuPass · G0045
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- Sowbug · G0054
- PROMETHIUM · G0056
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT39 · G0087
- WIRTE · G0090
- Silence · G0091
- Kimsuky · G0094
- Machete · G0095
- APT41 · G0096
- APT-C-36 · G0099
- Rocke · G0106
- Whitefly · G0107
- Blue Mockingbird · G0108
- Chimera · G0114
- Fox Kitten · G0117
- Indrik Spider · G0119
- Sidewinder · G0121
- Mustang Panda · G0129
- Transparent Tribe · G0134
- BackdoorDiplomacy · G0135
- Ferocious Kitten · G0137
- TeamTNT · G0139
- Aquatic Panda · G0143
- Ember Bear · G1003
- Earth Lusca · G1006
- SideCopy · G1008
- LuminousMoth · G1014
- FIN13 · G1016
- Volt Typhoon · G1017
- TA2541 · G1018
- Mustard Tempest · G1020
- ToddyCat · G1022
- APT5 · G1023
- Akira · G1024
- INC Ransom · G1032
- RedCurl · G1039
- APT42 · G1044
- Storm-1811 · G1046
- Velvet Ant · G1047
- VOID MANTICORE · G1055
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.