Detection of Renamed Living off the Land Binaries
This detection targets threat actors attempting to evade security defenses by renaming native Windows binaries to circumvent signature-based detection or security policy enforcement.
Adversaries frequently employ masquerading techniques to bypass security controls by renaming legitimate Windows binaries (Living Off the Land Binaries, or LOLBAS) to mimic benign system files or other applications. This technique allows threat actors to execute malicious code or perform unauthorized tasks using trusted, signed utilities while evading signature-based detections or policy-driven enforcement.
The detection logic focuses on the mismatch between the process name attribute and the original file name metadata. By analyzing process execution events from EDR telemetry, defenders can identify instances where a known LOLBAS tool - as defined by the LOLBAS project - is executing under an alias. This behavioral indicator is highly relevant for detecting defense evasion, as it often precedes lateral movement, credential access, or data exfiltration stages. Security teams should prioritize tuning to account for legitimate vendor-specific software that may copy or rename system binaries for internal application compatibility.
Impact
Successful execution of renamed LOLBAS binaries can lead to unauthorized code execution, persistence, and privilege escalation within the environment. Because these binaries are digitally signed by Microsoft, they are often overlooked by traditional security tools, increasing the risk of stealthy, long-term compromises that bypass standard host-based protections.
Recommendation
- Deploy the provided Sigma rule to identify process name mismatches for known LOLBAS binaries.
- Enable Sysmon Event ID 1 or Windows Event Log Security 4688 to ensure the capture of process name, original file name, and command-line execution telemetry.
- Use the Common Information Model (CIM) to map process execution data to the Endpoint data model to ensure detection consistency.
- Tune the detection rule to account for authorized MSI installers and known vendor application behavior that legitimately uses renamed system binaries to reduce false positives.
Immediate actions
Deploy process rename detection logic
Mitigations
Review and allowlist authorized vendor applications that perform renaming
Detection coverage 1
Detect Renamed Windows LOLBAS Execution
mediumDetects execution of a Windows native binary where the process name does not match the original file name attribute, indicating potential masquerading.
Detection queries are available on the platform. Get full rules →