EXPLORE
← Back to Explore
T1036

Masquerading

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitor...

ContainersESXiLinuxmacOSWindows
616
Detections
5
Sources
20
Threat Actors

BY SOURCE

498sublime67elastic39sigma11splunk_escu1crowdstrike_cql

PROCEDURES (143)

General Monitoring51 detections

Auto-extracted: 51 detections for general monitoring

Attachment31 detections

Auto-extracted: 31 detections for attachment

Authentication Monitoring21 detections

Auto-extracted: 21 detections for authentication monitoring

Email Security21 detections

Auto-extracted: 21 detections for email security

Email20 detections

Auto-extracted: 20 detections for email

Phish16 detections

Auto-extracted: 16 detections for phish

Script Execution Monitoring15 detections

Auto-extracted: 15 detections for script execution monitoring

Phish13 detections

Auto-extracted: 13 detections for phish

Base6413 detections

Auto-extracted: 13 detections for base64

Attachment13 detections

Auto-extracted: 13 detections for attachment

Process Creation Monitoring13 detections

Auto-extracted: 13 detections for process creation monitoring

Bypass12 detections

Auto-extracted: 12 detections for bypass

Impersonat12 detections

Auto-extracted: 12 detections for impersonat

Network Connection Monitoring12 detections

Auto-extracted: 12 detections for network connection monitoring

Credential12 detections

Auto-extracted: 12 detections for credential

Service10 detections

Auto-extracted: 10 detections for service

Impersonat8 detections

Auto-extracted: 8 detections for impersonat

Dump8 detections

Auto-extracted: 8 detections for dump

Obfuscat8 detections

Auto-extracted: 8 detections for obfuscat

Email7 detections

Auto-extracted: 7 detections for email

Bypass7 detections

Auto-extracted: 7 detections for bypass

Suspicious7 detections

Auto-extracted: 7 detections for suspicious

Office6 detections

Auto-extracted: 6 detections for office

Base646 detections

Auto-extracted: 6 detections for base64

Phish6 detections

Auto-extracted: 6 detections for phish

Masquerad6 detections

Auto-extracted: 6 detections for masquerad

Suspicious6 detections

Auto-extracted: 6 detections for suspicious

Encrypt5 detections

Auto-extracted: 5 detections for encrypt

Ransomware5 detections

Auto-extracted: 5 detections for ransomware

Obfuscat5 detections

Auto-extracted: 5 detections for obfuscat

Service5 detections

Auto-extracted: 5 detections for service

Service5 detections

Auto-extracted: 5 detections for service

Suspicious5 detections

Auto-extracted: 5 detections for suspicious

Credential5 detections

Auto-extracted: 5 detections for credential

Service5 detections

Auto-extracted: 5 detections for service

Api4 detections

Auto-extracted: 4 detections for api

Encrypt4 detections

Auto-extracted: 4 detections for encrypt

Masquerad4 detections

Auto-extracted: 4 detections for masquerad

Credential4 detections

Auto-extracted: 4 detections for credential

Credential4 detections

Auto-extracted: 4 detections for credential

Unusual4 detections

Auto-extracted: 4 detections for unusual

Obfuscat4 detections

Auto-extracted: 4 detections for obfuscat

Suspicious4 detections

Auto-extracted: 4 detections for suspicious

Phish4 detections

Auto-extracted: 4 detections for phish

Attachment4 detections

Auto-extracted: 4 detections for attachment

Unusual4 detections

Auto-extracted: 4 detections for unusual

Service4 detections

Auto-extracted: 4 detections for service

Download4 detections

Auto-extracted: 4 detections for download

Suspicious4 detections

Auto-extracted: 4 detections for suspicious

Encrypt4 detections

Auto-extracted: 4 detections for encrypt

Download4 detections

Auto-extracted: 4 detections for download

Evasion3 detections

Auto-extracted: 3 detections for evasion

Anomal3 detections

Auto-extracted: 3 detections for anomal

Cloud3 detections

Auto-extracted: 3 detections for cloud

Credential3 detections

Auto-extracted: 3 detections for credential

Child Process3 detections

Auto-extracted: 3 detections for child process

Bypass3 detections

Auto-extracted: 3 detections for bypass

Inject3 detections

Auto-extracted: 3 detections for inject

Service3 detections

Auto-extracted: 3 detections for service

Kernel3 detections

Auto-extracted: 3 detections for kernel

Cloud3 detections

Auto-extracted: 3 detections for cloud

Evasion3 detections

Auto-extracted: 3 detections for evasion

Evasion3 detections

Auto-extracted: 3 detections for evasion

Child Process2 detections

Auto-extracted: 2 detections for child process

Api2 detections

Auto-extracted: 2 detections for api

Office2 detections

Auto-extracted: 2 detections for office

Attachment2 detections

Auto-extracted: 2 detections for attachment

Evasion2 detections

Auto-extracted: 2 detections for evasion

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Impersonat2 detections

Auto-extracted: 2 detections for impersonat

Download2 detections

Auto-extracted: 2 detections for download

Ransomware2 detections

Auto-extracted: 2 detections for ransomware

Driver2 detections

Auto-extracted: 2 detections for driver

Impersonat2 detections

Auto-extracted: 2 detections for impersonat

Api2 detections

Auto-extracted: 2 detections for api

Base642 detections

Auto-extracted: 2 detections for base64

Http2 detections

Auto-extracted: 2 detections for http

Inject2 detections

Auto-extracted: 2 detections for inject

Attachment2 detections

Auto-extracted: 2 detections for attachment

Office2 detections

Auto-extracted: 2 detections for office

Macro2 detections

Auto-extracted: 2 detections for macro

Http2 detections

Auto-extracted: 2 detections for http

Evasion2 detections

Auto-extracted: 2 detections for evasion

Bypass2 detections

Auto-extracted: 2 detections for bypass

Privilege2 detections

Auto-extracted: 2 detections for privilege

Parent Process2 detections

Auto-extracted: 2 detections for parent process

Unusual1 detections

Auto-extracted: 1 detections for unusual

Persist1 detections

Auto-extracted: 1 detections for persist

Masquerad1 detections

Auto-extracted: 1 detections for masquerad

Anomal1 detections

Auto-extracted: 1 detections for anomal

Office1 detections

Auto-extracted: 1 detections for office

Obfuscat1 detections

Auto-extracted: 1 detections for obfuscat

Inject1 detections

Auto-extracted: 1 detections for inject

Token1 detections

Auto-extracted: 1 detections for token

Aws1 detections

Auto-extracted: 1 detections for aws

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Child Process1 detections

Auto-extracted: 1 detections for child process

Attachment1 detections

Auto-extracted: 1 detections for attachment

Macro1 detections

Auto-extracted: 1 detections for macro

Remote1 detections

Auto-extracted: 1 detections for remote

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Office1 detections

Auto-extracted: 1 detections for office

Unusual1 detections

Auto-extracted: 1 detections for unusual

Cloud1 detections

Auto-extracted: 1 detections for cloud

Aws1 detections

Auto-extracted: 1 detections for aws

Persist1 detections

Auto-extracted: 1 detections for persist

Token1 detections

Auto-extracted: 1 detections for token

Impersonat1 detections

Auto-extracted: 1 detections for impersonat

Masquerad1 detections

Auto-extracted: 1 detections for masquerad

Email1 detections

Auto-extracted: 1 detections for email

Download1 detections

Auto-extracted: 1 detections for download

Child Process1 detections

Auto-extracted: 1 detections for child process

Persist1 detections

Auto-extracted: 1 detections for persist

Email1 detections

Auto-extracted: 1 detections for email

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Command Line Monitoring1 detections

Auto-extracted: 1 detections for command line monitoring

Kernel1 detections

Auto-extracted: 1 detections for kernel

Bypass1 detections

Auto-extracted: 1 detections for bypass

Credential1 detections

Auto-extracted: 1 detections for credential

Lsass1 detections

Auto-extracted: 1 detections for lsass

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Unusual1 detections

Auto-extracted: 1 detections for unusual

Lsass1 detections

Auto-extracted: 1 detections for lsass

Privilege1 detections

Auto-extracted: 1 detections for privilege

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Oauth1 detections

Auto-extracted: 1 detections for oauth

Privilege1 detections

Auto-extracted: 1 detections for privilege

Persist1 detections

Auto-extracted: 1 detections for persist

Suspicious1 detections

Auto-extracted: 1 detections for suspicious

Inject1 detections

Auto-extracted: 1 detections for inject

Http1 detections

Auto-extracted: 1 detections for http

Oauth1 detections

Auto-extracted: 1 detections for oauth

Oauth1 detections

Auto-extracted: 1 detections for oauth

Email1 detections

Auto-extracted: 1 detections for email

Shellcode1 detections

Auto-extracted: 1 detections for shellcode

Parent Process1 detections

Auto-extracted: 1 detections for parent process

Kernel1 detections

Auto-extracted: 1 detections for kernel

Persist1 detections

Auto-extracted: 1 detections for persist

Token1 detections

Auto-extracted: 1 detections for token

Exfiltrat1 detections

Auto-extracted: 1 detections for exfiltrat

Unusual1 detections

Auto-extracted: 1 detections for unusual

Unusual1 detections

Auto-extracted: 1 detections for unusual

Download1 detections

Auto-extracted: 1 detections for download

DETECTIONS (616)

Abnormal Process ID or Lock File Created
elasticmedium
Abuse: Cloudflare Workers Hosted EvilTokens Domain Structure
sublimehigh
Adobe branded PDF file linking to a password-protected file from untrusted sender
sublimehigh
Agent Spoofing - Multiple Hosts Using Same Agent
elastichigh
Attachment with encrypted zip (unsolicited)
sublimemedium
Attachment with macro calling executable
sublimehigh
Attachment with unscannable encrypted zip
sublimemedium
Attachment: .csproj with suspicious commands
sublimehigh
Attachment: 7z Archive Containing RAR File
sublimemedium
Attachment: Any .sap file (unsolicited)
sublimelow
Attachment: Any HTML file within archive (unsolicited)
sublimemedium
Attachment: Archive containing disallowed file type
sublimelow
Attachment: Archive containing HTML file with file scheme link
sublimehigh
Attachment: Archive with embedded CHM file
sublimemedium
Attachment: Archive with embedded EXE file
sublimehigh
Attachment: Archive with pdf, txt and wsf files
sublimemedium
Attachment: Base64 encoded bash command in filename
sublimehigh
Attachment: Calendar file with invisible Unicode characters
sublimehigh
Attachment: Calendar invite from recently registered domain
sublimehigh
Attachment: Callback phishing solicitation via image file
sublimehigh
Attachment: Callback phishing solicitation via pdf file
sublimehigh
Attachment: Callback phishing solicitation via text-based file
sublimemedium
Attachment: DocX embedded binary
sublimehigh
Attachment: DOCX with hyperlink targeting recipient address
sublimemedium
Attachment: DOCX with malicious document template artifacts
sublimemedium
Attachment: Double base64-encoded zip file in HTML smuggling attachment
sublimehigh
Attachment: Embedded VBScript in MHT file
sublimemedium
Attachment: EML containing a base64 encoded script
sublimehigh
Attachment: EML file contains HTML attachment with login portal indicators
sublimehigh
Attachment: EML file with HTML attachment (unsolicited)
sublimemedium
Attachment: EML file with IPFS links
sublimemedium
Attachment: EML with embedded Javascript in SVG file
sublimehigh
Attachment: EML with Encrypted ZIP
sublimelow
Attachment: EML with link to credential phishing page
sublimehigh
Attachment: EML with QR code redirecting to Cloudflare challenges
sublimelow
Attachment: EML with SharePoint files shared from GoDaddy federated tenants
sublimelow
Attachment: EML with Sharepoint link likely unrelated to sender
sublimemedium
Attachment: EML with suspicious indicators
sublimemedium
Attachment: Emotet heavily padded doc in zip file
sublimehigh
Attachment: Employment contract update with suspicious file naming
sublimehigh
Attachment: Encrypted PDF With Credential Harvesting Indicators
sublimemedium
Attachment: Encrypted PDF with credential theft body
sublimemedium
Attachment: Encrypted PDF with credential theft language in EML
sublimemedium
Attachment: Encrypted ZIP containing VHDX file
sublimemedium
Attachment: Encrypted zip file with payment-related lure
sublimemedium
Attachment: Excel file with suspicious template identifier
sublimehigh
Attachment: Excel Web Query File (IQY)
sublimehigh
Attachment: Fake attachment image lure
sublimemedium
Attachment: Fake Slack installer
sublimehigh
Attachment: Fake Zoom installer
sublimehigh
Attachment: File execution via Javascript
sublimemedium
Attachment: Filename containing Unicode braille pattern blank character
sublimehigh
Attachment: Filename containing Unicode right-to-left override character
sublimehigh
Attachment: Finance themed PDF with observed phishing template
sublimemedium
Attachment: HTML attachment with Javascript location
sublimehigh
Attachment: HTML file contains exclusively Javascript
sublimemedium
Attachment: HTML file with excessive 'const' declarations and abnormally long timeouts
sublimehigh
Attachment: HTML file with excessive padding and suspicious patterns
sublimehigh
Attachment: HTML smuggling 'body onload' linking to suspicious destination
sublimehigh
Attachment: HTML smuggling 'body onload' with high entropy and suspicious text
sublimehigh
Attachment: HTML smuggling with atob and high entropy via calendar invite
sublimehigh
Attachment: HTML smuggling with base64 encoded ZIP file
sublimemedium
Attachment: HTML smuggling with concatenation obfuscation
sublimehigh
Attachment: HTML smuggling with decimal encoding
sublimehigh
Attachment: HTML smuggling with embedded base64-encoded executable
sublimehigh
Attachment: HTML smuggling with embedded base64-encoded ISO
sublimehigh
Attachment: HTML smuggling with eval and atob
sublimehigh
Attachment: HTML smuggling with eval and atob via calendar invite
sublimehigh
Attachment: HTML smuggling with excessive line break obfuscation
sublimehigh
Attachment: HTML smuggling with excessive string concatenation and suspicious patterns
sublimemedium
Attachment: HTML smuggling with fromCharCode and other signals
sublimehigh
Attachment: HTML smuggling with hex strings
sublimemedium
Attachment: HTML smuggling with high entropy and other signals
sublimehigh
Attachment: HTML smuggling with raw array buffer
sublimehigh
Attachment: HTML smuggling with RC4 decryption
sublimehigh
Attachment: HTML smuggling with ROT13
sublimehigh
Attachment: HTML smuggling with setTimeout
sublimehigh
Attachment: HTML smuggling with unescape
sublimehigh
Attachment: HTML with emoji-to-character map
sublimehigh
Attachment: HTML with hidden body
sublimehigh
Attachment: HTML with JavaScript functions for HTTP requests
sublimehigh
Attachment: ICS calendar file with base64 encoded recipient address in URL parameters
sublimehigh
Attachment: ICS calendar file with QR code containing recipient email address
sublimehigh
Attachment: ICS calendar file with suspicious product identifier
sublimemedium
Attachment: ICS calendar invite with financial lure and suspicious link
sublimemedium
Attachment: ICS calendar with embedded file from internal sender with SPF failure
sublimehigh
Attachment: ICS file with AWS Lambda URL
sublimemedium
Attachment: ICS file with excessive custom properties
sublimemedium
Attachment: ICS file with non-Gregorian calendar scale
sublimemedium
Attachment: ICS voicemail lure with suspicious link
sublimemedium
Attachment: ICS with embedded document
sublimelow
Attachment: ICS with embedded Javascript in SVG file
sublimehigh
Attachment: ICS with employee policy review lure
sublimehigh
Attachment: JavaScript file with suspicious base64-encoded executable
sublimehigh
Attachment: JPEG with gd-jpeg creator and suspicious file name
sublimehigh
Attachment: Legal themed message or PDF with suspicious indicators
sublimemedium
Attachment: Link file with UNC path
sublimemedium
Attachment: Link to Doubleclick.net open redirect
sublimemedium
Attachment: Macro files containing MHT content
sublimemedium
Attachment: Malformed OLE file
sublimehigh
Attachment: Microsoft OAuth credential harvesting via EML with embedded malicious links
sublimehigh
Attachment: MS Office or RTF file with Shell.Explorer.1 com object with embedded LNK
sublimemedium
Attachment: MS OOXML file created by Administrator with zero edit time
sublimehigh
Attachment: MSI installer file
sublimemedium
Attachment: Office file contains OLE relationship to credential phishing page
sublimehigh
Attachment: Office file with credential phishing URLs
sublimemedium
Attachment: Office file with document sharing and browser instruction lures
sublimehigh
Attachment: Office file with suspicious function calls or downloaded file path
sublimehigh
Attachment: OLE external relationship containing file scheme link to executable filetype
sublimehigh
Attachment: OLE external relationship containing file scheme link to IP address
sublimehigh
Attachment: Password-protected PDF with fake document indicators
sublimemedium
Attachment: PDF Attachment with links to workers.dev
sublimemedium
Attachment: PDF file with low reputation link to ZIP file (unsolicited)
sublimemedium
Attachment: PDF file with low reputation links to suspicious filetypes (unsolicited)
sublimemedium
Attachment: PDF generated with wkhtmltopdf tool and default title
sublimelow
Attachment: PDF Object Hash - Encrypted PDFs with fake payment notification
sublimemedium
Attachment: PDF Object Hash associated with a fake invoice and a W-9
sublimehigh
Attachment: PDF Object Hash associated with fake Canada Revenue Agency documents
sublimemedium
Attachment: PDF Object Hash with Blue File Icon
sublimemedium
Attachment: PDF proposal with credential theft indicators
sublimehigh
Attachment: PDF with a suspicious string and single URL
sublimehigh
Attachment: PDF with base64 JavaScript and eval functions
sublimemedium
Attachment: PDF with embedded box-lure and javascript
sublimemedium
Attachment: PDF with embedded Javascript
sublimemedium
Attachment: PDF with JSFck obfuscation
sublimehigh
Attachment: PDF with link to DMG file download
sublimemedium
Attachment: PDF with link to zip containing a wsf file
sublimehigh
Attachment: PDF with localhost IP in EXIF title metadata
sublimemedium
Attachment: PDF with multistage landing - ClickUp abuse
sublimehigh
Attachment: PDF with password in filename matching body text
sublimemedium
Attachment: PDF with ReportLab library and default metadata
sublimelow
Attachment: PDF with secure document acknowledgment prompt
sublimemedium
Attachment: PDF with self-service platform links with self sender or blank recipients
sublimemedium
Attachment: PDF with split QR code
sublimemedium
Attachment: PDF with suspicious HeadlessChrome metadata
sublimemedium
Attachment: PDF with suspicious language and redirect to suspicious file type
sublimehigh
Attachment: PDF with suspicious link and action-oriented language
sublimehigh
Attachment: PDF with suspicious view document characteristics
sublimemedium
Attachment: Potential sandbox evasion in Office file
sublimehigh
Attachment: PowerPoint with suspicious hyperlink
sublimehigh
Attachment: Python generated PDF with link
sublimemedium
Attachment: QR code link with base64-encoded recipient address
sublimehigh
Attachment: QR code with encoded recipient targeting and redirect indicators
sublimehigh
Attachment: QR code with recipient targeting and special characters
sublimehigh
Attachment: QR code with suspicious URL patterns in EML file
sublimehigh
Attachment: QR code with userinfo portion
sublimehigh
Attachment: RFC822 containing suspicious file sharing language with links from untrusted sender
sublimemedium
Attachment: RTF file with suspicious link
sublimemedium
Attachment: RTF with embedded content
sublimemedium
Attachment: Self-sender PDF with minimal content and view prompt
sublimehigh
Attachment: SFX archive containing commands
sublimemedium
Attachment: Single-page PDF with S3-hosted HTML link
sublimemedium
Attachment: Small text file with link containing recipient email address
sublimemedium
Attachment: Suspicious employee policy update document lure
sublimemedium
Attachment: Suspicious PDF created with headless browser
sublimehigh
Attachment: SVG file with HTML entity encoded href attributes
sublimemedium
Attachment: SVG file with hyperlinks and cursor styling
sublimemedium
Attachment: SVG files with evasion elements
sublimehigh
Attachment: TAR file with RAR type
sublimehigh
Attachment: Web files with suspicious comments
sublimehigh
Attachment: WinRAR CVE-2025-8088 exploitation
sublimehigh
Attachment: XLSX file with suspicious print titles metadata
sublimehigh
Attachment: ZIP containing Office binary with embedded DLL
sublimemedium
Attachment: ZIP file with CVE-2026-0866 exploit
sublimemedium
Attachment: ZIP filename mismatch
sublimelow
BEC with unusual reply-to or return-path mismatch
sublimehigh
BEC/Fraud: Reply-chain manipulation with urgent keywords and self-reply
sublimemedium
Benefits enrollment impersonation
sublimehigh
Binary Executed from Shared Memory Directory
elastichigh
Body HTML: Comment with 24-character hex token
sublimelow
Body HTML: Recipient SLD in HTML class
sublimemedium
Body: CSS clamp() font obfuscation with suspicious URL
sublimemedium
Body: CSS Hidden text via clip-path
sublimemedium
Body: CSS zero-value calc() obfuscation
sublimemedium
Body: Embedded email headers indicative of thread hijacking/abuse
sublimemedium
Body: Fake secure email portal with HTML obfuscation
sublimehigh
Body: HTML whitespace stuffing with short initial message
sublimemedium
Body: Invisible Unicode obfuscation student loan callback phishing
sublimemedium
Body: Suspicious date format
sublimemedium
Body: Suspicious table template fingerprint
sublimemedium
Body: Yellow highlighted text markers
sublimelow
Brand impersonation: Coinbase with suspicious links
sublimemedium
Brand impersonation: DocuSign with embedded QR code
sublimehigh
Brand impersonation: File sharing notification with template artifacts
sublimelow
Brand impersonation: Microsoft logo in HTML with fake quarantine release notification
sublimehigh
Brand impersonation: Microsoft Planner with suspicious link
sublimemedium
Brand impersonation: QuickBooks notification from Intuit themed company name
sublimemedium
Brand Impersonation: ShareFile
sublimemedium
Brand impersonation: SharePoint PDF attachment with credential theft language
sublimemedium
Brand impersonation: Stripe notification
sublimemedium
Brand impersonation: Zoom
sublimemedium
Business Email Compromise (BEC) attempt with masked recipients and reply-to mismatch (unsolicited)
sublimemedium
Callback phishing via Adobe Sign comment
sublimehigh
Callback phishing via calendar invite
sublimemedium
Callback phishing via DocuSign comment
sublimehigh
Callback phishing via Intuit service abuse
sublimemedium
Callback phishing via Zelle Service Abuse
sublimemedium
Callback phishing via Zoho service abuse
sublimemedium
Callback phishing: Social Security Administration fraud
sublimemedium
Callback phishing: SumUp infrastructure abuse
sublimehigh