heroui logo

Windows Renamed Python Binary was Executed

Splunk Security Content

View Source
Summary
This anomaly rule detects when a Python binary is renamed on disk and subsequently executed, a common defense-evasion tactic. It flags processes where the on-disk original_file_name that should reflect the legitimate Python binary (e.g., py*, python*, ipyw*) does not align with the actual running process name. The query aggregates endpoint process data (from Sysmon EventID 1 and CrowdStrike ProcessRollup2) to identify cases where a Python executable has been renamed and executed, while excluding obvious non-threats and common legitimate Python variants. It normalizes and validates the original_file_name, ensuring it matches a renamed Python pattern and that the running process_name isn’t a standard Python executable. Time bounds (firstTime/lastTime) are captured to correlate activity and establish a window of suspicious behavior. The rule maps to MITRE techniques T1036.003 (Masquerading) and T1059.006 (Python) and aligns with Windows defense-evasion trends. It acknowledges potential false positives when legitimate Python deployments use atypical names, and it ties to an analyst workflow for deeper investigation (e.g., process lineage and parent_process details). The analytic story emphasizes “Living Off The Land” behavior and masquerade tactics in Windows environments. The detection is designed for endpoint security tooling (Splunk) using CIM-normalized fields and EDR telemetry across supported data sources to surface renamed Python binaries that may indicate adversarial execution attempts.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
ATT&CK Techniques
  • T1036
  • T1059
  • T1036.003
  • T1059.006
Created: 2026-10-05