Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1036.005

T1036.005Match Legitimate Resource Name or Location

T1036.005 — Match Legitimate Resource Name or Location is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 61 detection use cases covering it and 41 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
61Use cases
41Articles
0Sub-techniques
1Tactic

Use cases covering this technique (61)

Attacker Tools On Endpoint ESCU actions · alerting P Windows LOLBAS Executed Outside Expected Path ESCU actions · hunting P Windows MSC EvilTwin Directory Path Manipulation ESCU actions · alerting P Windows Process Execution From ProgramData ESCU actions · hunting P Windows Process Execution in Temp Dir ESCU actions · hunting P Windows Suspicious Process File Path ESCU actions · alerting P [LLM] VMware-impersonating cron jobs drop JSP webshell (vmware-perf-update.jsp) Bespoke install · alerting DSΣPDDCS [LLM] HoneyMyte DLL side-load: renamed Sangfor 'defender.exe' loading malicious libngs.dll Bespoke install · hunting DSΣPDDCS [LLM] CoolClient injection target: masqueraded 'synchost.exe' (svchost typosquat) execution Bespoke install · alerting DSΣPDDCS [LLM] HoneyMyte Defender exclusion for fake 'Microsoft\Windows Defender' path via WMIC MSFT_MpPreference Bespoke install · alerting DSΣPDDCS [LLM] CoolClient sideloader staging: xcopy clones legit Windows Defender folder into fake Microsoft\Windows Defender dir Bespoke install · hunting DSΣPDDCS [LLM] HoneyMyte DLL side-load: renamed Sangfor defender.exe loads malicious libngs.dll from fake Defender dir Bespoke exploit · alerting DSΣPDDCS [LLM] macOS root LaunchDaemon persistence dropped by untrusted process (Apple crash-reporter impersonation) Bespoke install · hunting DSΣPCS [LLM] CornFlake RAT persistence via svchost32.exe masquerade in %APPDATA% Bespoke install · alerting DSΣPDDCS [LLM] CornFlake C2 egress from masqueraded svchost32.exe in AppData Bespoke c2 · hunting DSΣPDDCS [LLM] Cavern Manticore WinDirStat DLL side-load of fake uxtheme.dll (Cavern backdoor) Bespoke install · alerting DSΣP [LLM] Masqueraded uxtheme.dll dropped outside Windows dirs via SysAid/RMM deployment (Cavern Manticore) Bespoke delivery · alerting DSΣPDDCS [LLM] AppDomainManager hijacking config artifact dropped in user-writable path (Screening Serpens/UNC1549) Bespoke exploit · hunting DSΣPDDCS [LLM] SleeperGem payload drop: native binary written to hidden ~/.local/share/gcm/ Bespoke install · alerting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS [LLM] Velora macOS backdoor launchctl persistence (com.apple.Terminal.profiler.plist) Bespoke install · hunting DSΣPCS [LLM] axios RAT dropped artifacts: renamed PowerShell wt.exe + campaign 6202033 files Bespoke install · alerting DSΣPDDCS [LLM] Java/Spring drops & runs svchosts.exe (svchost masquerade) — Jackson typosquat implant Bespoke install · alerting DSΣPDDCS [LLM] Jackson typosquat Cobalt Strike implant hash sighting (Win + macOS/Linux) Bespoke install · hunting DSΣPDDCS [LLM] macOS.Gaslight LaunchAgent persistence masquerading as com.apple.system.services.activity Bespoke install · alerting DSΣPCS [LLM] easy-day-js stealer persistence masquerading as Node tooling (NodePackages / LaunchAgent / systemd) Bespoke install · alerting DSΣPDDCS [LLM] SPECTRALVIPER DLL side-load: IntelAudioService.exe (renamed dtlupdate.exe) loads DtlCrashCatch.dll Bespoke install · alerting DSΣPDDCS [LLM] Bun runtime download to /tmp from a node process during npm install Bespoke delivery · alerting DSPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] axios RAT Windows persistence: %PROGRAMDATA%\wt.exe drop + %TEMP%\6202033.vbs/.ps1 staging Bespoke install · alerting DSΣPDDCS [LLM] DNS/HTTPS exfil to sentry.anyclaw.store (Codex token C2 masquerading as Sentry) Bespoke c2 · alerting DSΣPDDCS [LLM] DebugChromium.exe execution (Laravel-Lang stealer Windows artifact) Bespoke install · alerting DSΣPDDCS [LLM] Stealer or VBS launcher dropped into .laravel_locale temp directory Bespoke install · alerting DSΣPDDCS [LLM] Python backdoor self-daemonisation via __DAEMONIZED=1 spawned by VS Code helper or node Bespoke install · hunting DSΣPDDCS [LLM] TeamPCP rope.pyz Dropper Infection Markers on Linux Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor PicassoLoader drop to %AppData%\WinDataScope\Update.js Bespoke install · alerting DSΣPDDCS [LLM] FrostyNeighbor Cobalt Strike beacon ViberPC.dll image load Bespoke install · hunting DSΣPDDCS [LLM] Hidden .fullgc cryptominer binary written to /ql/data/db/ Bespoke install · alerting DSΣPDDCS [LLM] Qinglong .fullgc cryptominer execution with nohup backgrounding Bespoke install · alerting DSΣPDD [LLM] whisper.dll loaded / svchost.exe spawned outside services.exe (GopherWhisper JabGopher injection) Bespoke install · alerting DSΣPDDCS [LLM] Stage-2 implant masquerading as node-health-check daemon (/tmp/.kh, /tmp/.ns) Bespoke install · alerting DSΣPDD [LLM] launchctl persistence registering zsh.profiler service from non-admin location Bespoke install · alerting DSΣPDDCS [LLM] macOS file write of profiler binary to com.apple.Terminal masquerade path Bespoke install · alerting DSΣPDDCS [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] IoliteLabs Stage-2 regsvr32 LOLbin loading ntuser DLL from fake Chrome\ChromeUpdate path Bespoke install · alerting DSΣPDD [LLM] msbuild.exe dropped to Startup folder (TeamPCP telnyx Windows persistence) Bespoke install · alerting DSΣPDDCS [LLM] Linux user-systemd sysmon persistence drop (~/.config/sysmon/sysmon.py + sysmon.service) Bespoke install · alerting DSΣPDDCS [LLM] PowerShell masquerading as Windows Terminal at %PROGRAMDATA%\wt.exe (Axios RAT Windows stage) Bespoke install · alerting DSΣPDDCS [LLM] SlimAgent / BeardShell DLL load with implant filename outside System32 Bespoke install · alerting DSΣPDDCS [LLM] PlugX DLL side-load — G DATA Avk.exe running from C:\Users\Public\GDatas\ Bespoke install · alerting DSΣPDD [LLM] Scavenger loader/install.js dropped into node_modules (known SHA256 or filename match) Bespoke delivery · hunting DSΣPDD [LLM] DynoWiper schtask.exe / *_update.exe execution from C:\inetpub\pub\ Bespoke install · alerting DSΣPDDCS [LLM] DynoWiper deployment from shared inetpub\pub directory (Sandworm, Poland Dec 2025) Bespoke install · alerting DSΣP [LLM] NosyDoor AppDomainManager hijack: UevAppMonitor.exe executing from non-standard path Bespoke install · alerting DSΣP [LLM] NosyDoor persistence: scheduled task 'OneDrive Reporting Task-S-1-5-21-' under Microsoft folder Bespoke install · alerting DSΣP [LLM] NosyDoor dropper file artefacts in C:\Windows\Microsoft.NET\Framework Bespoke install · alerting DSP [LLM] MuddyWater Fooder loader (OsUpdater.exe) execution from Downloads Bespoke install · alerting DSΣPDDCS [LLM] LittleDaemon / DaemonicLogistics update-hijack URL pattern (popup_4.2.0.2246.dll, /update/updateInfo.bzp, /update/file6.bdat, /update/file2. Bespoke delivery · alerting DSΣP [LLM] DaemonicLogistics fake-Tencent payload drop (logo.gif at %PROGRAMDATA%\Tencent\QQUpdateMgr\UpdateFiles) Bespoke install · alerting DSΣP [LLM] Polyfill malware C2: contact with googie-anaiytics homograph or kuurza redirect Bespoke c2 · alerting DSΣPDDCS [LLM] Process execution from masquerade directory C:\$Windows.~SXK (Discord/Roblox stealer) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (41)