Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1036

T1036Masquerading

T1036 — Masquerading is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 18 detection use cases covering it and 6 threat-intel articles citing it.

Defense Evasion
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
6Articles
12Sub-techniques
1Tactic

Sub-techniques (12)

Use cases covering this technique (18)

Cisco NVM - Non-Network Binary Making Network Connection ESCU actions · hunting P Executables Or Script Creation In Suspicious Path ESCU actions · hunting P Executables Or Script Creation In Temp Path ESCU actions · hunting P Linux Possible System Binary Backdoor ESCU actions · hunting P Linux Suspicious Staging of Alternate System Files ESCU actions · hunting P Suspicious writes to windows Recycle Bin ESCU actions · alerting P Windows Bluetooth Service Installed From Uncommon Location ESCU actions · hunting P Windows Debugger Tool Execution ESCU actions · hunting P Windows Masquerading Msdtc Process ESCU actions · alerting P Windows NetSupport RMM DLL Loaded By Uncommon Process ESCU actions · hunting P Windows SoftEther VPN Masquerading as Legitimate Binary ESCU actions · alerting P Windows Suspicious QEMU Execution ESCU actions · alerting P Windows TinyCC Shellcode Execution ESCU actions · alerting P Suspicious writes to System Volume Information ESCU actions · hunting P [LLM] XCSSET v40 worming: non-IDE process modifying multiple Xcode .pbxproj files Bespoke install · alerting DSPCS [LLM] SleeperGem: ruby process C2 contact to Forgejo host git.disroot.org Bespoke c2 · alerting DSΣPCS [LLM] Exfiltration to attacker-controlled Sentry ingest endpoint (onering crate) Bespoke actions · alerting DSΣPDDCS [LLM] Scavenger Stealer sandbox-evasion marker file %TEMP%\SCVNGR_VM created Bespoke install · alerting DSΣPDDCS

Articles citing this technique (6)