216.73.216.233

T1036.003: T1036.003

View on MITRE ATT&CK The MITRE Corporation · Published 10/02/2020 21:03 · Modified 31/03/2026 20:49

Essential information

MITRE technique ID
T1036.003
Confidence
100/100
Revoked
No
Published
10/02/2020 21:03
Modified
31/03/2026 20:49
Author / Source
The MITRE Corporation

Aliases

Rename Legitimate Utilities

Platforms

windows macos linux

Description

Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control mechanisms may be in place for legitimate utilities adversaries are capable of abusing, including both built-in binaries and tools such as PSExec, AutoHotKey, and IronPython.(Citation: LOLBAS Main Site)(Citation: Huntress Python Malware 2025)(Citation: The DFIR Report AutoHotKey 2023)(Citation: Splunk Detect Renamed PSExec) It may be possible to bypass those security mechanisms by renaming the utility prior to utilization (ex: rename `rundll32.exe`).(Citation: Elastic Masquerade Ball) An alternative case occurs when a legitimate utility is copied or moved to a different directory and renamed to avoid detections based on these utilities executing from non-standard paths.(Citation: F-Secure CozyDuke)

Kill chain phases

Kill chainPhase
mitre-attack defense-evasion

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references