
Summary
This anomaly detection rule identifies execution of a popular third-party Windows binary whose process name does not match its original file name attribute, a common masquerading technique used to evade defenses. It ingests endpoint process telemetry from Sysmon EventID 1 and CrowdStrike ProcessRollup2, mapped to the Endpoint data model. The Splunk search queries the Endpoint.Processes datamodel to exclude entries with unknown original_file_name, and cross-references a lookup named renamed_popular_3rd_party_binaries to obtain expected original_file_name and associated metadata. It then applies case-insensitive checks to detect when the actual process_name diverges from the original_file_name (with or without .exe adjustments) or when process_name does not contain the original_file_name. When a mismatch is found, the rule outputs key context including the process, original_file_name, process_path, parent process details, user, destination, and vendor_product, along with firstTime and lastTime stamps, and a mapped Windows-specific renamed-3rd-party-was-executed filter for actionable review. The analytic narrative aligns with Masquerading (T1036.003) and is supported by an analytic story that references Living Off The Land and Windows Defense Evasion tactics. This rule helps surface potential defense evasion by validating the integrity of a binary’s apparent filename against its actual original name, particularly for widely deployed third-party tools that adversaries may rename to blend in with a host’s software ecosystem.
Categories
- Endpoint
Data Sources
- Process
ATT&CK Techniques
- T1036
- T1036.003
Created: 2026-10-05