MITRE ATT&CK Technique
T1036.005
2 queries tagged with this technique.
View on MITRE ATT&CK →
-
Analytics Rules
Detect Dll Masquerading As Microsoft Defender
DLLs pretending to be Microsoft Defender via resource-level publisher/original-filename metadata — a Vidar Stealer TTP.
-
Hunting
Hunt Linux Process Argv0 Vs Executable Mismatch
Linux processes where argv[0] doesn't match the actual binary that was executed — a process wearing another process's name tag.