Esc
Rename Legitimate Utilities - T1036.003
(ATT&CK® Technique)
Definition
Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for system utilities adversaries are capable of abusing. It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename rundll32.exe). An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on system utilities executing from non-standard paths.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.