{"id":"T1036.006","name":"Space after Filename","url":"https://attack.mitre.org/techniques/T1036/006","tactics":["stealth"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0292","stix_id":"x-mitre-detection-strategy--16462629-5b36-4bb6-a565-de4df01f75d4","name":"Masquerading via Space After Filename - Behavioral Detection Strategy","url":"https://attack.mitre.org/detectionstrategies/DET0292","analytics":[{"id":"AN0812","stix_id":"x-mitre-analytic--778e2c18-2b26-4dd4-b4b2-3f8310d57a07","name":"Analytic 0812","description":"Detection of file execution where the file name contains a trailing space to masquerade as a known executable. Adversaries may exploit the way command line interpreters handle file names with trailing whitespace.","url":"https://attack.mitre.org/detectionstrategies/DET0292#AN0812","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"application or system execution logs","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"ExecutableNameTrailingSpace","description":"This detection may vary based on how different shells and file systems treat trailing spaces. Normalize or regex-match file names with trailing space."},{"field":"UserContext","description":"Monitor for untrusted or lower-privileged users executing suspicious scripts with disguised names."},{"field":"TimeWindow","description":"Tune for execution patterns during off-hours to reduce false positives."}],"live":true,"detection_strategies":["DET0292"],"techniques":["T1036.006"]},{"id":"AN0813","stix_id":"x-mitre-analytic--773188c7-6191-4ba4-ad39-b67ed8578dd9","name":"Analytic 0813","description":"Execution of renamed or dropped files with a trailing space to deceive users or analysts, especially in LaunchAgents or LaunchDaemons.","url":"https://attack.mitre.org/detectionstrategies/DET0292#AN0813","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process events","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"fs:fsusage","channel":"filesystem activity","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"fs-fsusage"}],"mutable_elements":[{"field":"FilenamePattern","description":"Tunable regex or path rule to match common masquerade attempts (e.g., 'Terminal .app')."},{"field":"TargetPath","description":"Analytic can be scoped to key directories (e.g., /Users/Library/LaunchAgents/)."},{"field":"UserContext","description":"Focus detection on suspicious user sessions or service creation under non-admin users."}],"live":true,"detection_strategies":["DET0292"],"techniques":["T1036.006"]}],"live":true,"version":"1.0","techniques":["T1036.006"]}],"sigma_rules":[{"id":"b6e2a2e3-2d30-43b1-a4ea-071e36595690","title":"Space After Filename - macOS","author":"remotephone","status":"test","level":"low","date":"2021-11-20","modified":"2023-01-04","description":"Detects attempts to masquerade as legitimate files by adding a space to the end of the filename.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1036.006/T1036.006.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.stealth","attack.t1036.006"],"path":"rules/macos/process_creation/proc_creation_macos_space_after_filename.yml","techniques":["T1036.006"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}