Windows Renamed Command Interpreter was Executed
The following analytic identifies a Windows command interpreter process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an…
Description
The following analytic identifies a Windows command interpreter process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Detection logic
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- crowdstrike_processrollup2sysmon_eventid_1
Known benign triggers
- 3rd party software binaries sharing the same name as Windows command interpreter binaries may trigger false positives.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| attack.mitre.org/techniques/T1036/ | 7 |
| attack.mitre.org/techniques/T1036/003/ | 8 |
| attack.mitre.org/techniques/T1059/ | 7from 2 sources |
| redcanary.com/threat-detection-report/techniques/rename-system-utilities/ | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- 6f4611be-076e-4fa8-bc78-466588a71442
- Tagged by the source as
- Living Off The LandMasquerading - Rename System UtilitiesSuspicious Command-Line ExecutionsWater GamayunWindows Defense Evasion TacticsEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint
Licence
- Published under
- Apache License 2.0Read the licence
- Attribution
- Required
- Obtained under
- Apache-2.0Read the origin licence
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1