{"id":"T1036.004","name":"Masquerade Task or Service","url":"https://attack.mitre.org/techniques/T1036/004","tactics":["stealth"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0117","stix_id":"x-mitre-detection-strategy--45665335-5bf0-4553-9398-ea40d550cbff","name":"Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution","url":"https://attack.mitre.org/detectionstrategies/DET0117","analytics":[{"id":"AN0324","stix_id":"x-mitre-analytic--51a23f35-4a11-4119-935a-1ffebcda2839","name":"Analytic 0324","description":"Creation or modification of Windows services or scheduled tasks with names or descriptions mimicking legitimate entries, followed by anomalous execution of untrusted binaries or LOLBAS.","url":"https://attack.mitre.org/detectionstrategies/DET0117#AN0324","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:System","channel":"EventCode=7045","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-system"},{"name":"WinEventLog:Security","channel":"EventCode=4698","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"TaskNameSimilarityThreshold","description":"Similarity threshold for comparing new task/service names to known legitimate names (e.g., Levenshtein distance)"},{"field":"BinaryReputationScore","description":"Confidence level required for allowing a binary, often from unsigned or untrusted source"},{"field":"ExecutionContext","description":"Whether the execution came from SYSTEM, service accounts, or user contexts"}],"live":true,"detection_strategies":["DET0117"],"techniques":["T1036.004"]},{"id":"AN0325","stix_id":"x-mitre-analytic--5a9c1860-23ae-455e-bcab-0e0f91af5548","name":"Analytic 0325","description":"Creation or modification of `systemd` service units or cron jobs using deceptive naming and untrusted command paths, often followed by lateral network activity or privilege escalation.","url":"https://attack.mitre.org/detectionstrategies/DET0117#AN0325","platforms":["Linux"],"log_source_references":[{"name":"auditd:CONFIG_CHANGE","channel":"/var/log/audit/audit.log","data_component":"DC0012","data_component_name":"Scheduled Job Modification","log_source_slug":"auditd-config-change"},{"name":"linux:osquery","channel":"scheduled/real-time","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"linux-osquery"},{"name":"linux:cron","channel":"cron activity","data_component":"DC0005","data_component_name":"Scheduled Job Metadata","log_source_slug":"linux-cron"}],"mutable_elements":[{"field":"UnitFilePath","description":"Unusual or user-space paths for systemd unit files"},{"field":"ServiceNameDeviation","description":"Detect units with names similar to legitimate ones (e.g., `networks.service` instead of `network.service`)"},{"field":"ExecStartPath","description":"Track uncommon or suspicious binaries in `ExecStart=` directives"}],"live":true,"detection_strategies":["DET0117"],"techniques":["T1036.004"]},{"id":"AN0326","stix_id":"x-mitre-analytic--7e3c05c9-5e49-416c-a0c9-eb7631ea5e7e","name":"Analytic 0326","description":"Creation of LaunchAgents or LaunchDaemons with names resembling known system services but executing non-Apple signed code or scripts.","url":"https://attack.mitre.org/detectionstrategies/DET0117#AN0326","platforms":["macOS"],"log_source_references":[{"name":"fs:fileevents","channel":"/Library/LaunchDaemons/*.plist, ~/Library/LaunchAgents/*.plist","data_component":"DC0005","data_component_name":"Scheduled Job Metadata","log_source_slug":"fs-fileevents"},{"name":"macos:endpointsecurity","channel":"ES_EVENT_TYPE_NOTIFY_EXEC","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"subsystem=com.apple.launchservices","data_component":"DC0041","data_component_name":"Service Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"PlistLabelSimilarity","description":"Detect plists with labels that closely resemble legitimate ones (e.g., `com.apple.updates.plist`)"},{"field":"UnsignedBinaryExecution","description":"Toggle sensitivity for unsigned binaries or scripts launched by daemons"},{"field":"UserContext","description":"Scope detection based on whether LaunchAgent ran in user or system context"}],"live":true,"detection_strategies":["DET0117"],"techniques":["T1036.004"]}],"live":true,"version":"1.0","techniques":["T1036.004"]}],"sigma_rules":[{"id":"1cfac73c-be78-4f9a-9b08-5bde0c3953ab","title":"Operation Wocao Activity","author":"Florian Roth (Nextron Systems), frack113","status":"test","level":"high","date":"2019-12-20","modified":"2022-10-09","description":"Detects activity mentioned in Operation Wocao report","references":["https://www.fox-it.com/en/news/whitepapers/operation-wocao-shining-a-light-on-one-of-chinas-hidden-hacking-groups/","https://twitter.com/SBousseaden/status/1207671369963646976"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.discovery","attack.stealth","attack.t1012","attack.t1036.004","attack.t1027","attack.execution","attack.t1053.005","attack.t1059.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/Operation-Wocao/proc_creation_win_apt_wocao.yml","techniques":["T1012","T1036.004","T1027","T1053.005","T1059.001"],"cves":[]},{"id":"74ad4314-482e-4c3e-b237-3f7ed3b9ca8d","title":"Operation Wocao Activity - Security","author":"Florian Roth (Nextron Systems), frack113","status":"test","level":"high","date":"2019-12-20","modified":"2022-11-27","description":"Detects activity mentioned in Operation Wocao report","references":["https://web.archive.org/web/20200226212615/https://www.fox-it.com/en/news/whitepapers/operation-wocao-shining-a-light-on-one-of-chinas-hidden-hacking-groups/","https://web.archive.org/web/20200226212615/https://resources.fox-it.com/rs/170-CAK-271/images/201912_Report_Operation_Wocao.pdf","https://twitter.com/SBousseaden/status/1207671369963646976"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.discovery","attack.stealth","attack.t1012","attack.t1036.004","attack.t1027","attack.execution","attack.t1053.005","attack.t1059.001","detection.emerging-threats"],"path":"rules-emerging-threats/2019/TA/Operation-Wocao/win_security_apt_wocao.yml","techniques":["T1012","T1036.004","T1027","T1053.005","T1059.001"],"cves":[]},{"id":"9f8573c9-22b4-40e3-89c1-72bc2b8d49ab","title":"Scheduled Task Creation Masquerading as System Processes","author":"Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"high","date":"2025-02-05","modified":null,"description":"Detects the creation of scheduled tasks that involve system processes, which may indicate malicious actors masquerading as or abusing these processes to execute payloads or maintain persistence.","references":["https://tria.ge/241015-l98snsyeje/behavioral2"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.stealth","attack.t1053.005","attack.t1036.004","attack.t1036.005"],"path":"rules/windows/process_creation/proc_creation_win_schtasks_system_process.yml","techniques":["T1053.005","T1036.004","T1036.005"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}