Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1036

T1036Masquerading

T1036 — Masquerading is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 16 detection use cases covering it and 7 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
7Articles
12Sub-techniques
1Tactic

Sub-techniques (12)

Use cases covering this technique (16)

Cisco NVM - Non-Network Binary Making Network Connection ESCU actions · hunting P Executables Or Script Creation In Suspicious Path ESCU actions · hunting P Executables Or Script Creation In Temp Path ESCU actions · hunting P Suspicious writes to windows Recycle Bin ESCU actions · alerting P Windows Bluetooth Service Installed From Uncommon Location ESCU actions · hunting P Windows Debugger Tool Execution ESCU actions · hunting P Windows Masquerading Msdtc Process ESCU actions · alerting P Windows NetSupport RMM DLL Loaded By Uncommon Process ESCU actions · hunting P Windows SoftEther VPN Masquerading as Legitimate Binary ESCU actions · alerting P Windows Suspicious QEMU Execution ESCU actions · alerting P Windows TinyCC Shellcode Execution ESCU actions · alerting P Suspicious writes to System Volume Information ESCU actions · hunting P [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] Masqueraded 'Autoupdate' scheduled task run by PowerShell loader (ACR Stealer persistence) Bespoke install · alerting DSΣPDDCS [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) Bespoke actions · alerting DSΣPDDCS [LLM] Scavenger Stealer sandbox-evasion marker file %TEMP%\SCVNGR_VM created Bespoke install · alerting DSΣPDDCS

Articles citing this technique (7)