{"id":"T1036.005","name":"Match Legitimate Resource Name or Location","url":"https://attack.mitre.org/techniques/T1036/005","tactics":["stealth"],"platforms":["Containers","ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0347","stix_id":"x-mitre-detection-strategy--b667390b-a805-401d-9e02-929204825114","name":"Detection Strategy for Masquerading via Legitimate Resource Name or Location","url":"https://attack.mitre.org/detectionstrategies/DET0347","analytics":[{"id":"AN0983","stix_id":"x-mitre-analytic--61256fb2-d490-4e1d-b308-665a2d68ec64","name":"Analytic 0983","description":"Detects processes or binaries executed from trusted directories (e.g., System32) or using trusted names (e.g., svchost.exe) where the metadata, hash, or parent process does not align with legitimate activity patterns.","url":"https://attack.mitre.org/detectionstrategies/DET0347#AN0983","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=11","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"trusted_directory_list","description":"Paths such as C:\\Windows\\System32 that adversaries may abuse"},{"field":"process_baseline_age","description":"Time window to determine process novelty (e.g., 30 days)"}],"live":true,"detection_strategies":["DET0347"],"techniques":["T1036.005"]},{"id":"AN0984","stix_id":"x-mitre-analytic--adf3e421-95ec-4b5a-9c00-0262cb888c0a","name":"Analytic 0984","description":"Detects renamed binaries or scripts placed into trusted paths like /usr/bin or /lib with mismatched metadata or unexpected creation/modification times.","url":"https://attack.mitre.org/detectionstrategies/DET0347#AN0984","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"rename","data_component":"DC0020","data_component_name":"Process Modification","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"Filesystem modifications to trusted paths","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"monitored_paths","description":"Set of system or application directories considered sensitive or trusted"},{"field":"hash_validation_window","description":"Timeframe during which a newly created file should have its hash validated (e.g., within 5 minutes of write)"}],"live":true,"detection_strategies":["DET0347"],"techniques":["T1036.005"]},{"id":"AN0985","stix_id":"x-mitre-analytic--466a2102-fcb3-4372-9a8d-ad8fe34e94ec","name":"Analytic 0985","description":"Detects binaries or launch daemons in /System/Library or /Applications with mismatched bundle names, unexpected metadata, or improper installation origin.","url":"https://attack.mitre.org/detectionstrategies/DET0347#AN0985","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"log collect from launchd and process start","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"filesystem monitoring of exec/open","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"expected_bundle_names","description":"List of known application names and paths to validate against"},{"field":"signed_by_apple_check","description":"Toggle to enforce checks for Apple-signed binaries in trusted directories"}],"live":true,"detection_strategies":["DET0347"],"techniques":["T1036.005"]},{"id":"AN0986","stix_id":"x-mitre-analytic--c9bdc7a6-ff19-46e9-a534-fa2fd3e0a193","name":"Analytic 0986","description":"Detects malicious containers or pods using names, labels, or namespaces that mimic legitimate workloads; also checks for image layer mismatches and unauthorized resource deployments.","url":"https://attack.mitre.org/detectionstrategies/DET0347#AN0986","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:apiserver","channel":"Resource creation and update logs","data_component":"DC0028","data_component_name":"Image Metadata","log_source_slug":"kubernetes-apiserver"},{"name":"containerd:events","channel":"Docker or containerd image pulls and process executions","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"containerd-events"}],"mutable_elements":[{"field":"trusted_namespace_list","description":"List of namespaces that should not be used by unprivileged users or workloads"},{"field":"image_baseline_hashes","description":"Reference hashes of approved container images"}],"live":true,"detection_strategies":["DET0347"],"techniques":["T1036.005"]},{"id":"AN0987","stix_id":"x-mitre-analytic--d16be21c-6df4-4648-91cd-36152dafa38d","name":"Analytic 0987","description":"Detects VIBs, scripts, or binaries placed into directories like /bin or /etc/vmware with names mimicking standard ESXi components. Also monitors unauthorized creation of services.","url":"https://attack.mitre.org/detectionstrategies/DET0347#AN0987","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"Exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"esxi-vmkernel"},{"name":"esxi:vmkernel","channel":"module load","data_component":"DC0016","data_component_name":"Module Load","log_source_slug":"esxi-vmkernel"},{"name":"esxi:hostd","channel":"Service events","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"esxi-hostd"},{"name":"esxi:hostd","channel":"task creation events","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"esxi-hostd"}],"mutable_elements":[{"field":"esxi_baseline_file_list","description":"Known good binaries and their expected paths"},{"field":"service_creation_alert_threshold","description":"Threshold for unknown service names or mismatched digital signatures"}],"live":true,"detection_strategies":["DET0347"],"techniques":["T1036.005"]}],"live":true,"version":"1.0","techniques":["T1036.005"]}],"sigma_rules":[{"id":"01d2e2a1-5f09-44f7-9fc1-24faa7479b6d","title":"Uncommon Svchost Parent Process","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-08-15","modified":"2022-06-28","description":"Detects an uncommon svchost parent process","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_svchost_uncommon_parent_process.yml","techniques":["T1036.005"],"cves":[]},{"id":"13c02350-4177-4e45-ac17-cf7ca628ff5e","title":"Files With System DLL Name In Unsuspected Locations","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2024-06-24","modified":null,"description":"Detects the creation of a file with the \".dll\" extension that has the name of a System DLL in uncommon or unsuspected locations. (Outisde of \"System32\", \"SysWOW64\", etc.).\nIt is highly recommended to perform an initial baseline before using this rule in production.\n","references":["Internal Research"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/file/file_event/file_event_win_creation_system_dll_files.yml","techniques":["T1036.005"],"cves":[]},{"id":"2ad78473-6978-40f5-b8f1-89c7e1c27a1a","title":"RedSun - Conhost.exe Spawned by TieringEngineService.exe","author":"Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost","status":"experimental","level":"high","date":"2026-04-17","modified":null,"description":"Detects two stages of the RedSun post-exploitation process chain that deliver a SYSTEM-level shell to the attacker's interactive session.\nObserved process chain\n  services.exe\n    → TieringEngineService.exe\n      → conhost.exe             (SYSTEM, CommandLine: bare path, no arguments)\n        → cmd.exe / shell       (SYSTEM, TerminalSessionId = attacker's session)\n\nStage 1 — TieringEngineService.exe spawns argument-less conhost.exe:\n  After winning the oplock + Cloud Files mount point race, the malicious TieringEngineService.exe (RedSun.exe copied to System32, started via CoCreateInstance\n  / services.exe) detects it is NT AUTHORITY\\SYSTEM and calls LaunchConsoleInSessionId().\n  This opens \\\\.\\pipe\\REDSUN, reads the attacker's session ID, duplicates the SYSTEM token, re-stamps it with that session ID via SetTokenInformation(TokenSessionId), then\n  calls CreateProcessAsUser to spawn conhost.exe with no arguments.\n\nStage 2 — Shell spawned from rogue conhost.exe (EDR sources with GrandParentImage):\n  The rogue SYSTEM conhost.exe spawns a shell (cmd.exe, PowerShell, etc.) as SYSTEM in the attacker's interactive session.\n  On EDR sources that expose GrandParentImage, the full three-level chain (TieringEngineService.exe → conhost.exe → shell) can be matched directly.\n  The legitimate TieringEngineService.exe is a headless COM server that is unlikely to spawn conhost.exe under normal conditions.\n","references":["https://github.com/Nightmare-Eclipse/RedSun"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1134.002","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/RedSun/proc_creation_win_redsun_conhost_via_tiering_engine.yml","techniques":["T1134.002","T1036.005"],"cves":[]},{"id":"3711eee4-a808-4849-8a14-faf733da3612","title":"Greenbug Espionage Group Indicators","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-05-20","modified":"2023-03-09","description":"Detects tools and process executions used by Greenbug in their May 2020 campaign as reported by Symantec","references":["https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/greenbug-espionage-telco-south-asia"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.g0049","attack.execution","attack.t1059.001","attack.command-and-control","attack.t1105","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2020/TA/Greenbug/proc_creation_win_apt_greenbug_may20.yml","techniques":["T1059.001","T1105","T1036.005"],"cves":[]},{"id":"39466c42-c189-476a-989f-8cdb135c163a","title":"Small Sieve Malware File Indicator Creation","author":"Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-05-19","modified":null,"description":"Detects filename indicators that contain a specific typo seen used by the Small Sieve malware.","references":["https://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/small-sieve/NCSC-MAR-Small-Sieve.pdf"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Small-Sieve/file_event_win_malware_small_sieve_evasion_typo.yml","techniques":["T1036.005"],"cves":[]},{"id":"3f7f5b0b-5b16-476c-a85f-ab477f6dd24b","title":"Lazarus System Binary Masquerading","author":"Trent Liffick (@tliffick), Bartlomiej Czyz (@bczyz1)","status":"test","level":"high","date":"2020-06-03","modified":"2023-03-10","description":"Detects binaries used by the Lazarus group which use system names but are executed and launched from non-default location","references":["https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/07180244/Lazarus_Under_The_Hood_PDF_final.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2017/TA/Lazarus/proc_creation_win_apt_lazarus_binary_masquerading.yml","techniques":["T1036.005"],"cves":[]},{"id":"4922a5dd-6743-4fc2-8e81-144374280997","title":"Flash Player Update from Suspicious Location","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-10-25","modified":"2022-08-08","description":"Detects a flashplayer update from an unofficial location","references":["https://gist.github.com/roycewilliams/a723aaf8a6ac3ba4f817847610935cfb"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.stealth","attack.t1189","attack.execution","attack.t1204.002","attack.t1036.005"],"path":"rules/web/proxy_generic/proxy_susp_flash_download_loc.yml","techniques":["T1189","T1204.002","T1036.005"],"cves":[]},{"id":"5f87308a-0a5b-4623-ae15-d8fa1809bc60","title":"Suspicious Files in Default GPO Folder","author":"elhoim","status":"test","level":"medium","date":"2022-04-28","modified":null,"description":"Detects the creation of copy of suspicious files (EXE/DLL) to the default GPO storage folder","references":["https://redcanary.com/blog/intelligence-insights-november-2021/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/file/file_event/file_event_win_susp_default_gpo_dir_write.yml","techniques":["T1036.005"],"cves":[]},{"id":"7993792c-5ce2-4475-a3db-a3a5539827ef","title":"Exploit for CVE-2015-1641","author":"Florian Roth (Nextron Systems)","status":"stable","level":"critical","date":"2018-02-22","modified":"2021-11-27","description":"Detects Winword starting uncommon sub process MicroScMgmt.exe as used in exploits for CVE-2015-1641","references":["https://www.virustotal.com/en/file/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8/analysis/","https://www.hybrid-analysis.com/sample/5567408950b744c4e846ba8ae726883cb15268a539f3bb21758a466e47021ae8?environmentId=100"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.005","cve.2015-1641","detection.emerging-threats"],"path":"rules-emerging-threats/2015/Exploits/CVE-2015-1641/proc_creation_win_exploit_cve_2015_1641.yml","techniques":["T1036.005"],"cves":["CVE-2015-1641"]},{"id":"7cce6fc8-a07f-4d84-a53e-96e1879843c9","title":"Potential Binary Impersonating Sysinternals Tools","author":"frack113, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"test","level":"medium","date":"2021-12-20","modified":"2025-04-12","description":"Detects binaries that use the same name as legitimate sysinternals tools to evade detection.\nThis rule looks for the execution of binaries that are named similarly to Sysinternals tools.\nAdversary may rename their malicious tools as legitimate Sysinternals tools to evade detection.\n","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.stealth","attack.t1218","attack.t1202","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_tools_masquerading.yml","techniques":["T1218","T1202","T1036.005"],"cves":[]},{"id":"96036718-71cc-4027-a538-d1587e0006a7","title":"Windows Processes Suspicious Parent Directory","author":"vburov","status":"test","level":"low","date":"2019-02-23","modified":"2025-03-06","description":"Detect suspicious parent processes of well-known Windows processes","references":["https://web.archive.org/web/20180718061628/https://securitybytes.io/blue-team-fundamentals-part-two-windows-processes-759fe15965e2","https://www.carbonblack.com/2014/06/10/screenshot-demo-hunt-evil-faster-than-ever-with-carbon-black/","https://www.13cubed.com/downloads/windows_process_genealogy_v2.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.003","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_susp_proc_wrong_parent.yml","techniques":["T1036.003","T1036.005"],"cves":[]},{"id":"9f8573c9-22b4-40e3-89c1-72bc2b8d49ab","title":"Scheduled Task Creation Masquerading as System Processes","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-02-05","modified":null,"description":"Detects the creation of scheduled tasks that involve system processes, which may indicate malicious actors masquerading as or abusing these processes to execute payloads or maintain persistence.","references":["https://tria.ge/241015-l98snsyeje/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.stealth","attack.t1053.005","attack.t1036.004","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_schtasks_system_process.yml","techniques":["T1053.005","T1036.004","T1036.005"],"cves":[]},{"id":"a7c3e5f2-8b1d-4e9a-b6c2-3d7f5e8a9b4c","title":"RedSun - TieringEngineService.exe Detected as EICAR Test File","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"critical","date":"2026-04-17","modified":null,"description":"Detects Windows Defender (EventID 1119 - Remediation Action Failed) flagging TieringEngineService.exe\ndropped in a characteristic RS-{GUID} temporary directory, or the RedSun.exe process itself being present.\nThis covers the staging pattern used by RedSun, a Cloud Files API and opportunistic lock (oplock) based\nAV bypass/privilege escalation tool.\n\nRedSun works as follows:\n  1. Registers a Cloud Files sync root and creates a Cloud Files placeholder for TieringEngineService.exe under %TEMP%\\RS-{GUID}\\\n  2. The placeholder file carries EICAR test file content (Virus:DOS/EICAR_Test_File) to reliably trigger\n     a Defender scan and remediation attempt\n  3. Requests a batch oplock (FSCTL_REQUEST_BATCH_OPLOCK) on the placeholder file\n  4. When Defender attempts to scan/quarantine the file, the oplock triggers - holding the file open\n  5. During the oplock break window, RedSun swaps the mount point (junction) to redirect\n     \\\\?\\C:\\Windows\\System32 to the attacker-controlled temp path\n  6. This races the AV/OS into executing the malicious TieringEngineService.exe with elevated privileges\n","references":["https://github.com/Nightmare-Eclipse/RedSun/blob/7456cc8cf066f5e5fc6cdf7d3272a466ebd6b2f6/RedSun.cpp#L605","https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.stealth","attack.defense-impairment","attack.t1036.005","attack.t1685","attack.privilege-escalation","attack.t1055","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/RedSun/win_defender_exploit_redsun_tiering_engine_detected_as_eicar.yml","techniques":["T1036.005","T1685","T1055"],"cves":[]},{"id":"a80d927d-ac6e-443f-a867-e8d6e3897318","title":"Creation Of Pod In System Namespace","author":"Leo Tsaousis (@laripping)","status":"test","level":"medium","date":"2024-03-26","modified":null,"description":"Detects deployments of pods within the kube-system namespace, which could be intended to imitate system pods.\nSystem pods, created by controllers such as Deployments or DaemonSets have random suffixes in their names.\nAttackers can use this fact and name their backdoor pods as if they were created by these controllers to avoid detection.\nDeployment of such a backdoor container e.g. named kube-proxy-bv61v, could be attempted in the kube-system namespace alongside the other administrative containers.\n","references":["https://microsoft.github.io/Threat-Matrix-for-Kubernetes/techniques/Pod%20or%20container%20name%20similarily/"],"logsource":{"product":"kubernetes","category":"application","service":"audit"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/application/kubernetes/audit/kubernetes_audit_pod_in_system_namespace.yml","techniques":["T1036.005"],"cves":[]},{"id":"be58d2e2-06c8-4f58-b666-b99f6dc3b6cd","title":"Suspicious Process Masquerading As SvcHost.EXE","author":"Swachchhanda Shrawan Poudel","status":"test","level":"high","date":"2024-08-07","modified":null,"description":"Detects a suspicious process that is masquerading as the legitimate \"svchost.exe\" by naming its binary \"svchost.exe\" and executing from an uncommon location.\nAdversaries often disguise their malicious binaries by naming them after legitimate system processes like \"svchost.exe\" to evade detection.\n","references":["https://tria.ge/240731-jh4crsycnb/behavioral2","https://redcanary.com/blog/threat-detection/process-masquerading/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_svchost_masqueraded_execution.yml","techniques":["T1036.005"],"cves":[]},{"id":"d5866ddf-ce8f-4aea-b28e-d96485a20d3d","title":"Files With System Process Name In Unsuspected Locations","author":"Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2020-05-26","modified":"2026-07-28","description":"Detects the creation of an executable with a system process name in folders other than the system ones (System32, SysWOW64, etc.).\nIt is highly recommended to perform an initial baseline before using this rule in production.\n","references":["Internal Research"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/file/file_event/file_event_win_creation_system_file.yml","techniques":["T1036.005"],"cves":[]},{"id":"dd2a821e-3b07-4d3b-a9ac-929fe4c6ca0c","title":"Suspicious Scheduled Task Creation via Masqueraded XML File","author":"Swachchhanda Shrawan Poudel, Elastic (idea)","status":"test","level":"medium","date":"2023-04-20","modified":"2024-12-01","description":"Detects the creation of a scheduled task using the \"-XML\" flag with a file without the '.xml' extension. This behavior could be indicative of potential defense evasion attempt during persistence","references":["https://learn.microsoft.com/en-us/windows/win32/taskschd/daily-trigger-example--xml-","https://github.com/elastic/protections-artifacts/blob/084067123d3328a823b1c3fdde305b694275c794/behavior/rules/persistence_suspicious_scheduled_task_creation_via_masqueraded_xml_file.toml"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.stealth","attack.t1036.005","attack.t1053.005"],"path":"rules/windows/process_creation/proc_creation_win_schtasks_schedule_via_masqueraded_xml_file.yml","techniques":["T1036.005","T1053.005"],"cves":[]},{"id":"e22a6eb2-f8a5-44b5-8b44-a2dbd47b1144","title":"Potential MsiExec Masquerading","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-11-14","modified":"2023-02-21","description":"Detects the execution of msiexec.exe from an uncommon directory","references":["https://twitter.com/200_okay_/status/1194765831911215104"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.stealth","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_msiexec_masquerading.yml","techniques":["T1036.005"],"cves":[]},{"id":"e5f5c693-52d7-4de5-88ae-afbfbce85595","title":"Unsigned .node File Loaded","author":"Jonathan Beierle (@hullabrian)","status":"experimental","level":"medium","date":"2025-11-22","modified":null,"description":"Detects the loading of unsigned .node files.\nAdversaries may abuse a lack of .node integrity checking to execute arbitrary code inside of trusted applications such as Slack.\n.node files are native add-ons for Electron-based applications, which are commonly used for desktop applications like Slack, Discord, and Visual Studio Code.\nThis technique has been observed in the DripLoader malware, which uses unsigned .node files to load malicious native code into Electron applications.\n","references":["https://www.coreycburton.com/blog/driploader-case-study","https://github.com/CoreyCBurton/DripLoaderNG","https://www.electronjs.org/docs/latest/tutorial/native-code-and-electron"],"logsource":{"product":"windows","category":"image_load"},"tags":["attack.execution","attack.privilege-escalation","attack.persistence","attack.stealth","attack.t1129","attack.t1574.001","attack.t1036.005"],"path":"rules/windows/image_load/image_load_dll_unsigned_node_load.yml","techniques":["T1129","T1574.001","T1036.005"],"cves":[]},{"id":"f17211f1-1f24-4d0c-829f-31e28dc93cdd","title":"Uncommon Svchost Command Line Parameter","author":"Liran Ravich","status":"experimental","level":"high","date":"2025-11-14","modified":"2026-03-23","description":"Detects instances of svchost.exe running with an unusual or uncommon command line parameter by excluding known legitimate or common patterns.\nThis could point at a file masquerading as svchost, a process injection, or hollowing of a legitimate svchost instance.\n","references":["https://cardinalops.com/blog/the-art-of-anomaly-hunting-patterns-detection/","https://www.security.com/threat-intelligence/blackbyte-exbyte-ransomware","https://cloud.google.com/blog/topics/threat-intelligence/apt41-initiates-global-intrusion-campaign-using-multiple-exploits/","https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2018/03/08064518/Carbanak_APT_eng.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.stealth","attack.t1036.005","attack.t1055","attack.t1055.012"],"path":"rules/windows/process_creation/proc_creation_win_svchost_uncommon_command_line_flags.yml","techniques":["T1036.005","T1055","T1055.012"],"cves":[]},{"id":"f2e4b7d9-5c3a-4f8b-9e1d-7a6c2b3f4e5d","title":"RedSun - TieringEngineService.exe Staged in RS-Prefixed Temp Dir","author":"Swachchhanda Shrawan Poudel (Nextron Systems), @unresolvedhost","status":"experimental","level":"critical","date":"2026-04-17","modified":null,"description":"Detects the creation of a file named TieringEngineService.exe inside a directory whose path contains the RS- prefix characteristic\nof RedSun's staging directory (e.g. %TEMP%\\RS-{GUID}\\TieringEngineService.exe).\nRedSun registers a Cloud Files sync root under this RS-prefixed path and drops a masqueraded placeholder there as part of its oplock-based AV bypass and privilege escalation chain.\n\nThe RS-{GUID} directory name is generated by RedSun itself and has no legitimate system usage,\nmaking the combination of this path prefix and the TieringEngineService.exe filename a highly\nspecific indicator of RedSun activity.\n","references":["https://github.com/Nightmare-Eclipse/RedSun/blob/7456cc8cf066f5e5fc6cdf7d3272a466ebd6b2f6/RedSun.cpp#L591","https://deadeclipse666.blogspot.com/2026/04/public-disclosure-response-for-cve-2026.html"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.stealth","attack.t1036.005","detection.emerging-threats"],"path":"rules-emerging-threats/2026/Exploits/RedSun/file_event_win_exploit_redsun_indicators.yml","techniques":["T1036.005"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-26360","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}