Masquerading: Space after Filename T1036.006

Tactic: Stealth

Adversaries can hide a program's true filetype by changing the extension of a file. With certain file types (specifically this does not work with .app extensions), appending a space to the end of a filename will change how the file is processed by the operating system.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFexecProcess Execution

Authoring guide

These 3 rules share fields, values, and exclusions.

Fields filtered most (6 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
Image2ends_with 1, regex_match 1 , /[a-z0-9\s_\-\\./]+\s
event.type2eq 2start
CommandLine1ends_with 1
EventType1in 1exec, exec_event, executed
host.os.type1eq 1
process_name1ends_with 1

Top indicator values (9 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
21087
CommandLineends_with
1
EventTypein
exec
1206
EventTypein
exec_event
1150
EventTypein
executed
198
EventTypein
process_started
183
Imageends_with
1
Imageregex_match
/[a-z0-9\s_\-\\./]+\s
1
process_nameends_with
1

Exclusions (12 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagestarts_with
/opt/gitlab/sv/gitlab-exporter/
1
Imagestarts_with
/opt/nessus_agent/
1
Imagestarts_with
/tmp/ansible-admin/
1
process.argseq
runc
1
process.parent.argsin
./check_rubrik
1
process.parent.argsin
/etc/rubrik/start_stop_agent.sh
1
process.parent.argsin
/etc/rubrik/start_stop_bootstrap.sh
1
process.parent.argsin
/usr/bin/check_mk_agent
1
process_namein
find
1
process_namein
grep
1
process_namein
ls
1
process_namein
xkbcomp
1

Rules under this technique

These vendors publish rules tagged with this technique.

Domain: Endpoint

Platform (all)

Sigma 1 rule

Elastic 2 rules