Detection of Masquerading via System Processes in Non-Standard Paths
This brief addresses the detection of Windows system processes executing from unexpected file paths, a technique frequently used by threat actors for masquerading and defense evasion.
This threat brief focuses on the detection of Windows system processes that execute from non-standard directory paths. Attackers often utilize masquerading techniques by renaming malicious files to match legitimate system processes or moving them to unconventional directories to evade signature-based security controls. This activity is a common indicator of defense evasion, where adversaries attempt to blend malicious execution with legitimate system background tasks to bypass detection, gain persistent access, or facilitate privilege escalation. This analytic is designed for deployment within EDR platforms to monitor process execution paths against known legitimate Windows directory structures.
Attack Chain
- Attacker identifies a target environment and selects a legitimate system process name (e.g., svchost.exe, lsass.exe) to impersonate.
- Attacker prepares a malicious binary or a copy of a system utility with the chosen name.
- Attacker drops the file into a non-standard directory, such as a user-controlled folder or temporary directory, to avoid alerting file integrity monitors that watch System32.
- Attacker modifies permissions or registry keys (e.g., Run keys or Service configurations) to ensure the masqueraded process executes.
- The system process executes from the unexpected location upon system startup or trigger condition.
- Attacker leverages the masqueraded process context to execute malicious code, perform credential dumping, or establish command-and-control communication.
Impact
Successful masquerading can lead to persistent unauthorized access, privilege escalation, and execution of malicious payloads while remaining hidden from basic security monitoring. If an attacker successfully masquerades as a critical system process, they can gain significant control over the endpoint and potentially evade detection by security operations teams.
Recommendation
- Enable process creation logging (e.g., Sysmon Event ID 1 or Windows Event ID 4688) across all endpoints.
- Normalize endpoint process telemetry into the CIM (Common Information Model) or equivalent schema to ensure accurate path analysis.
- Deploy the provided Sigma rule to identify processes that match the names of legitimate Windows system binaries but execute outside of protected system directories (e.g., C:\Windows\System32).
- Tune the analytic by creating allowlists for third-party software that legitimately installs binaries into non-standard locations.
Immediate actions
Deploy Sigma detection rule to SIEM/EDR platform.
Mitigations
Review process execution logs for common installation paths of third-party software and update exclusion filters.
False positives in masquerading detection
Detection coverage 1
Detect System Processes Running From Unexpected Locations
mediumDetects system processes such as svchost.exe or lsass.exe executing from paths other than Windows System32 or SysWOW64.
Detection queries are available on the platform. Get full rules →