Back to results

Windows Renamed LOLBAS Binary was Executed

The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an…

Description

The following analytic identifies a LOLBAS process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code.

Detection logic

Detection requirements

Platform
LinuxmacOSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Known benign triggers

  • 3rd party software binaries sharing the same name as LOLBAS utilities may trigger false positives.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice