Detection of Masquerading via Renamed Third-Party Binaries
This analytic identifies potential defense evasion activity by detecting instances where common third-party software binaries are executed under a filename that does not match their original file name metadata.
Adversaries often rename legitimate binaries to masquerade as other files and evade security controls or file-based detection mechanisms. This analytic identifies a popular 3rd party software process being executed where the process name does not match its original file name attribute. This technique is frequently observed in post-exploitation scenarios, including ransomware distribution, where attackers attempt to blend malicious execution with legitimate activity or bypass simple allowlisting rules. Defenders should focus on telemetry that captures both the process name and the internal original file name metadata, typically available through Sysmon Event ID 1 or EDR-specific process events.
Impact
Successful masquerading via renaming can lead to unauthorized execution of tools, persistence mechanisms, or malicious payloads while evading signature-based security detections. This technique is commonly associated with broader adversary campaigns, including those involving ransomware like LockBit, where renaming binaries assists in initial deployment and execution on victim machines.
Recommendation
Deploy detection logic to identify mismatches between process execution names and internal binary metadata. Ensure that endpoint telemetry is properly mapped to the Endpoint data model within your SIEM. Tune the detection by creating an allowlist for any known legitimate organizational software that may use unconventional naming conventions.
- Enable Sysmon Event ID 1 (Process Creation) to capture the OriginalFileName field.
- Implement the detection logic below to identify renaming discrepancies.
- Investigate high-risk alerts using the provided drilldown links to analyze risk object associations over the previous 7 days.
- Monitor for activity associated with the 'Living Off The Land' analytic story.
Immediate actions
Deploy detection rule to identify renamed third-party binaries
Threat Hunt
Identify processes with mismatched OriginalFileName in audit logs
Data: Process creation events with OriginalFileName metadata
Detection coverage 1
Detect Renamed Third-Party Software Execution
mediumDetects the execution of known third-party binaries where the process name does not match the original file name metadata, a common indicator of masquerading.
Detection queries are available on the platform. Get full rules →