216.73.216.233

T1036.004: T1036.004

View on MITRE ATT&CK The MITRE Corporation · Published 10/02/2020 21:30 · Modified 27/03/2026 01:10

Essential information

MITRE technique ID
T1036.004
Confidence
100/100
Revoked
No
Published
10/02/2020 21:30
Modified
27/03/2026 01:10
Author / Source
The MITRE Corporation

Aliases

Masquerade Task or Service

Platforms

windows macos linux

Description

Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description.(Citation: TechNet Schtasks)(Citation: Systemd Service Units) Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones. Tasks or services contain other fields, such as a description, that adversaries may attempt to make appear legitimate.(Citation: Palo Alto Shamoon Nov 2016)(Citation: Fysbis Dr Web Analysis)

Kill chain phases

Kill chainPhase
mitre-attack defense-evasion

Marking (TLP)

TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references