Techniques › T1036 › T1036.001
T1036.001 Invalid Code Signature
stealth — macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
2
analytics
0
Sigma rules tagged attack.t1036.001
0
KEV CVEs mapped here
<p>Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. Adversaries can copy the metadata and signature information from a signed program, then use it as a template for an unsigned program. Files with invalid code signatures will fail digital signature validation checks, but they may appear more legitimate to users and security tools may improperly handle these files.</p><p>Unlike Code Signing, this activity will not result in a valid signature.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0031 Invalid Code Signature Execution Detection via Metadata and Behavioral Context v1.0
AN0089 WindowsExecution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.Tunable:
SignatureValidationResultParentProcessNameTimeWindowAN0090 macOSBinaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users.Tunable:CodeSigningStatusUserContextExecutablePathPrefix
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1036.001
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1036) 40
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Micah Babinski
· 2022-12-11 (modified 2023-03-05) · logsource: product=windows category=process_creation · 0c92f2e6-f08f-4b73-9216-ecb0ca634689
Detects the use of rcedit to potentially alter executable PE metadata properties, which could conceal efforts to rename system utilities for defense evasion.
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
· 2024-01-17 · logsource: product=windows category=process_creation · 12fbff88-16b5-4b42-9754-cd001a789fb3
Detects a CodePage modification using the "mode.com" utility to Russian language.
This behavior has been used by threat actors behind Dharma ransomware.
Author: Christian Burkard (Nextron Systems)
· 2021-10-26 (modified 2023-03-29) · logsource: product=windows category=process_creation · 1327381e-6ab0-4f38-b583-4c1b8346a56b
Detects potential evasion or obfuscation attempts using bogus path traversal via the commandline
Author: juju4, Jonhnathan Ribeiro, oscd.community
· 2019-01-16 (modified 2022-01-07) · logsource: product=windows category=process_creation · 15b75071-74cc-47e0-b4c6-b43744a62a2b
Detects suspicious process run from unusual locations
Author: Florian Roth (Nextron Systems)
· 2022-09-20 (modified 2023-02-14) · logsource: product=windows category=process_creation · 1a1ed54a-2ba4-4221-94d5-01dee560d71e
Detects uses of a renamed legitimate createdump.exe LOLOBIN utility to dump process memory
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-06-06 (modified 2023-02-03) · logsource: product=windows category=process_creation · 1c12727d-02bf-45ff-a9f3-d49806a3cf43
Detects the execution of a renamed version of the Plink binary
Author: Florian Roth (Nextron Systems)
· 2021-08-16 (modified 2026-06-29) · logsource: product=windows category=process_creation · 2e65275c-8288-4ab4-aeb7-6274f58b6b20
Detects usage of the SysInternals Procdump utility
Author: Joseliyo Sanchez, @Joseliyo_Jstnk
· 2023-06-02 (modified 2025-08-05) · logsource: product=linux category=process_creation · 312b42b1-bded-4441-8b58-163a3af58775
Detects a potentially suspicious execution of a process located in the '/tmp/' folder
Author: Micah Babinski, @micahbabinski
· 2023-05-07 · logsource: product=windows category=process_creation · 32e280f1-8ad4-46ef-9e80-910657611fbc
Detects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters.
This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that
are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
Author: Trent Liffick
· 2020-05-01 (modified 2024-01-15) · logsource: product=windows category=process_creation · 33339be3-148b-4e16-af56-ad16ec6c7e7b
Detects usage of findstr to identify and execute a lnk file as seen within the HHS redirect attack
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2020-01-28 (modified 2025-01-22) · logsource: product=windows category=process_creation · 340a090b-c4e9-412e-bb36-b4b16fe96f9b
Detects a renamed "dctask64.exe" execution, a signed binary by ZOHO Corporation part of ManageEngine Endpoint Central.
This binary can be abused for DLL injection, arbitrary command and process execution.
Author: Florian Roth (Nextron Systems)
· 2022-10-14 (modified 2024-08-29) · logsource: product=windows category=process_creation · 396f6630-f3ac-44e3-bfc8-1b161bc00c4e
Detects suspicious Windows Error Reporting manager (wermgr.exe) child process
Author: Florian Roth (Nextron Systems)
· 2018-03-13 (modified 2024-01-18) · logsource: product=windows category=process_creation · 3d7679bd-0c00-440c-97b0-3f204273e6c7
Detects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC
Author: Florian Roth (Nextron Systems), Tim Shelton
· 2019-01-16 (modified 2024-07-12) · logsource: product=windows category=process_creation · 3dfd06d2-eaf4-4532-9555-68aca59f57c4
Detects a potentially suspicious execution from an uncommon folder.
Author: Florian Roth (Nextron Systems)
· 2021-12-22 (modified 2022-12-25) · logsource: product=windows service=security · 45eb2ae2-9aa2-4c3a-99a5-6e5077655466
Detects the renaming of an existing computer account to a account name that doesn't contain a $ symbol as seen in attacks against CVE-2021-42287
Author: Sreeman
· 2020-04-17 (modified 2024-02-08) · logsource: product=windows category=process_creation · 4e762605-34a8-406d-b72e-c1a089313320
HxTsr.exe is a Microsoft compressed executable file called Microsoft Outlook Communications.
HxTsr.exe is part of Outlook apps, because it resides in a hidden "WindowsApps" subfolder of "C:\Program Files".
Any instances of hxtsr.exe not in this folder may be malware camouflaging itself as HxTsr.exe
Author: Micah Babinski, @micahbabinski
· 2023-05-08 · logsource: product=windows category=file_event · 4f1707b1-b50b-45b4-b5a2-3978b5a5d0d6
Detects the presence of unicode characters which are homoglyphs, or identical in appearance, to ASCII letter characters.
This is used as an obfuscation and masquerading techniques. Only "perfect" homoglyphs are included; these are characters that
are indistinguishable from ASCII characters and thus may make excellent candidates for homoglyph attack characters.
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
· 2022-01-04 (modified 2022-08-19) · logsource: product=windows category=process_creation · 515c8be5-e5df-4c5e-8f6d-a4a2f05e4b48
Detects uses of the createdump.exe LOLOBIN utility to dump process memory
Author: Florian Roth (Nextron Systems)
· 2022-02-26 (modified 2023-11-11) · logsource: product=windows category=process_creation · 52d097e2-063e-4c9c-8fbb-855c8948d135
Detects suspicious Windows Update Agent activity in which a wuauclt.exe process command line doesn't contain any command line flags
Author: Florian Roth (Nextron Systems)
· 2022-05-09 · logsource: product=windows service=security · 54f0434b-726f-48a1-b2aa-067df14516e4
Detects the extraction of password protected ZIP archives with suspicious file names. See the filename variable for more details on which file has been opened.
Author: Florian Roth (Nextron Systems)
· 2018-10-30 (modified 2025-10-19) · logsource: product=windows category=process_creation · 5afee48e-67dd-4e03-a783-f74259dcf998
Detects potential credential harvesting attempts through LSASS memory dumps using ProcDump.
This rule identifies suspicious command-line patterns that combine memory dump flags (-ma, -mm, -mp) with LSASS-related process markers.
LSASS (Local Security Authority Subsystem Service) contains sensitive authentication data including plaintext passwords, NTLM hashes, and Kerberos tickets in memory.
Attackers commonly dump LSASS memory to extract credentials for lateral movement and privilege escalation.
Author: Florian Roth (Nextron Systems), Modexp, Nasreddine Bencherchali (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems)
· 2020-02-18 (modified 2025-02-23) · logsource: product=windows category=process_creation · 646ea171-dded-4578-8a4d-65e9822892e3
Detects a process memory dump via "comsvcs.dll" using rundll32, covering multiple different techniques (ordinal, minidump function, etc.)
Author: Florian Roth (Nextron Systems)
· 2022-01-28 (modified 2023-02-08) · logsource: product=windows category=process_creation · 66e563f9-1cbd-4a22-a957-d8b7c0f44372
Detects suspicious use of XORDump process memory dumping utility
Author: Florian Roth (Nextron Systems)
· 2019-02-09 (modified 2023-11-09) · logsource: product=windows category=process_creation · 737e618a-a410-49b5-bec3-9e55ff7fbc15
Detects suspicious use of 'calc.exe' with command line parameters or in a suspicious directory, which is likely caused by some PoC or detection evasion.
Author: Florian Roth (Nextron Systems)
· 2022-01-11 (modified 2023-05-09) · logsource: product=windows category=process_creation · 79b06761-465f-4f88-9ef2-150e24d3d737
Detects uses of the SysInternals ProcDump utility in which ProcDump or its output get renamed, or a dump file is moved or copied to a different name
Author: Nextron Systems
· 2022-06-01 (modified 2023-02-06) · logsource: product=windows category=process_creation · 7a74da6b-ea76-47db-92cc-874ad90df734
Detects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), @gott_cyber
· 2019-06-29 (modified 2025-10-31) · logsource: product=windows category=process_creation · 949f1ffb-6e85-4f00-ae1e-c3c5b190d605
Detects a command line process that uses explorer.exe to launch arbitrary commands or binaries,
which is similar to cmd.exe /c, only it breaks the process tree and makes its parent a new instance of explorer spawning from "svchost"
Author: Florian Roth (Nextron Systems)
· 2018-03-18 (modified 2022-05-27) · logsource: product=windows category=process_creation · 9fff585c-c33e-4a86-b3cd-39312079a65f
Detects the creation of taskmgr.exe process in context of LOCAL_SYSTEM
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-08-12 (modified 2025-10-07) · logsource: product=windows category=file_event · b8fd0e93-ff58-4cbd-8f48-1c114e342e62
Detects Windows executables that write files with suspicious extensions
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community
· 2019-10-14 (modified 2023-03-07) · logsource: product=windows category=process_creation · c7942406-33dd-4377-a564-0f62db0593a3
Detects a code page switch in command line or batch scripts to a rare language
Author: Florian Roth (Nextron Systems)
· 2022-03-21 (modified 2022-09-08) · logsource: product=windows category=process_creation · cbec226f-63d9-4eca-9f52-dfb6652f24df
Detects suspicious parent processes that should not have any children or should only have a single possible child program
Author: Ilyas Ochkov, oscd.community
· 2019-10-25 (modified 2024-01-16) · logsource: product=windows service=security · cfeed607-6aa4-4bbd-9627-b637deb723c8
Detects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.
Author: Nasreddine Bencherchali (Nextron Systems), Joseliyo Sanchez, @Joseliyo_Jstnk
· 2024-01-19 · logsource: product=windows category=process_creation · d48c5ffa-3b02-4c0f-9a9e-3c275650dd0e
Detects a CodePage modification using the "mode.com" utility.
This behavior has been used by threat actors behind Dharma ransomware.
Author: Nasreddine Bencherchali (Nextron Systems), Florian Roth (Nextron Systems)
· 2022-04-06 (modified 2023-04-12) · logsource: product=windows category=process_creation · dee0a7a3-f200-4112-a99b-952196d81e42
Detects the use of "DumpMinitool.exe" a tool that allows the dump of process memory via the use of the "MiniDumpWriteDump"
Author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali (Nextron Systems)
· 2017-11-27 (modified 2026-07-28) · logsource: product=windows category=process_creation · e4a6b256-3e47-40fc-89d2-7a477edd6915
Detects the execution of a Windows system binary that is usually located in the system folder from an uncommon location.
Author: Florian Roth (Nextron Systems)
· 2022-03-14 · logsource: product=linux category=process_creation · ea3ecad2-db86-4a89-ad0b-132a10d2db55
Detects suspicious interactive bash as a parent to rather uncommon child processes
Author: Florian Roth (Nextron Systems)
· 2022-04-06 (modified 2023-04-12) · logsource: product=windows category=process_creation · eb1c4225-1c23-4241-8dd4-051389fde4ce
Detects suspicious ways to use the "DumpMinitool.exe" binary
Author: Nextron Systems, @Kostastsale
· 2022-06-01 (modified 2024-08-23) · logsource: product=windows category=process_creation · f3d39c45-de1a-4486-a687-ab126124f744
Detects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
Author: Nasreddine Bencherchali (Nextron Systems), Anish Bogati
· 2024-01-05 · logsource: product=windows category=process_creation · f53714ec-5077-420e-ad20-907ff9bb2958
Detects the execution of "forfiles" from a non-default location, in order to potentially spawn a custom "cmd.exe" from the current working directory.
Author: X__Junior (Nextron Systems)
· 2023-06-30 · logsource: product=windows category=process_creation · fabfb3a7-3ce1-4445-9c7c-3c27f1051cdd
Detects execution of "WerFault.exe" with the "-pr" commandline flag that is used to run files stored in the ReflectDebugger key which could be used to store the path to the malware in order to masquerade the execution flow