
Summary
This anomaly detects Windows command interpreter processes that execute under a binary name different from its original file name, a common defense-evasion tactic used to masquerade malicious activity. The rule relies on endpoint telemetry (EDR data) such as Sysmon EventID 1 and CrowdStrike ProcessRollup2 to compare the process name against the original_file_name attribute. It filters for mismatches with a lookup of renamed Windows command interpreter binaries, then reports key process details (destination, user, process and parent process information, timestamps) and prevalent metadata. The detection is normalized through the Splunk CIM and tailored for the Endpoint data model, enabling correlation with related risks and investigations. Known false positives include legitimate 3rd-party binaries that share names with Windows command interpreters. The rule maps to MITRE ATT&CK techniques T1036 (Masquerading) and T1059 (Command-Line/Interpreters).
Categories
- Endpoint
Data Sources
- Windows Registry
- Process
ATT&CK Techniques
- T1036
- T1059
- T1036.003
Created: 2026-10-05