Windows Renamed LOLBAS Binary was Executed
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an…
Description
The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.
Detection logic
Detection requirements
- Platform
- LinuxmacOSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source category
- crowdstrike_processrollup2sysmon_eventid_1
Known benign triggers
- 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| attack.mitre.org/techniques/T1036/ | 7 |
| attack.mitre.org/techniques/T1036/003/ | 8 |
| redcanary.com/threat-detection-report/techniques/rename-system-utilities/ | 2 |
From the source
- At source
- Open at source
- Upstream identifier
- 10c3850e-810d-41b4-a197-2f14d7883579
- Tagged by the source as
- Living Off The LandMasquerading - Rename System UtilitiesWater GamayunWindows Defense Evasion TacticsEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint
Licence
- Published under
- Apache License 2.0Read the licence
- Attribution
- Required
- Obtained under
- Apache-2.0Read the origin licence
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1