// MITRE ATT&CK

T1036.003 · Rename Legitimate Utilities

🎯 Stealth LinuxmacOSWindows Sub-technique

Sub-technique of T1036 · Masquerading.

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as...

How to detect & mitigate it

Detecting Rename Legitimate Utilities starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.