Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1055.013

T1055.013Process Doppelgänging

T1055.013 — Process Doppelgänging is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 2 detection use cases covering it and 1 threat-intel article citing it.

Defense EvasionPrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
2Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (2)

PowerShell PInvoke Process Injection API Chain ESCU actions · alerting P [LLM] Process Ghosting: executable created then deleted while backing a live process Bespoke install · hunting DSPCS

Articles citing this technique (1)