Windows Renamed Popular 3rd Party Software was Executed
The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an…
Description
The following analytic identifies a popular 3rd party software process being executed where it's process name does not match it's original file name attribute. Processes that have been renamed and executed may be an indicator that an adversary is attempting to evade defenses or execute malicious code.
Detection logic
Detection requirements
- Platform
- LinuxmacOSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
- Log source category
- crowdstrike_processrollup2sysmon_eventid_1
Known benign triggers
- 3rd party software binaries might have overlapping executable names.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| attack.mitre.org/techniques/T1036/ | 7 |
| attack.mitre.org/techniques/T1036/003/ | 8 |
| thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/ | 3from 2 sources |
| thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/ | 2from 2 sources |
From the source
- At source
- Open at source
- Upstream identifier
- cf6713c7-ac6b-4963-83a6-39f24ed10aa8
- Tagged by the source as
- Living Off The LandMasquerading - Rename System UtilitiesWater GamayunWindows Defense Evasion TacticsEndpointendpointSplunk CloudSplunk EnterpriseSplunk Enterprise Securityendpoint
Licence
- Published under
- Apache License 2.0Read the licence
- Attribution
- Required
- Obtained under
- Apache-2.0Read the origin licence
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1