
Summary
Detects Windows processes that have been renamed (original_file_name) and subsequently executed, indicating potential LOLBAS abuse and defense evasion. The rule ingests endpoint telemetry from EDRs (e.g., Sysmon EventID 1 and CrowdStrike ProcessRollup2) and cross-references with a local table of known LOLBAS binaries (renamed_lolbas_binaries). It filters for records where the original_file_name is known (not '-' or 'unknown') and where the actual process_name differs from the original_file_name, which may indicate an adversary renaming a utility to masquerade as a benign process. The detection operates on normalized CIM fields (Processes.original_file_name, Processes.process_name, and related process context such as dest, parent, user) and uses a lookup to enrich with a description. It outputs intermediate findings showing the LOLBAS binary renamed to a new path, and executed on a target destination, with associated process and user metadata. The analytic maps to MITRE ATT&CK technique T1036.003 (Masquerading: Rename System Utilities) and is complemented by drilldown and risk-search components for incident response. This rule supports detection of Windows-based defense evasion attempts that abuse legitimate-system utilities by renaming them and executing them to perform malicious tasks.
Categories
- Endpoint
Data Sources
- Script
- Image
- Windows Registry
- Process
ATT&CK Techniques
- T1036
- T1036.003
Created: 2026-10-05