#T1036.005 Match Legitimate Resource Name or Location
Technique
- Tactics: Defense Evasion
- Description:
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.(Citation: Aquasec Kubernetes Backdoor 2023)
- First Seen: Phishing Emails Used to Deploy KONNI Malware • 2020-08-14
-
24
Tagged Reports
-
16
Unique Authors
-
2,073
Active Days
Tagged Reports
2026-04-17
Break Glass Intelligence
2026-01-20
Picus Security
2026-01-13
Cyfirma
2025-08-13
Cyfirma
2025-02-12
Cyfirma
2024-09-12
Cyfirma
2023-02-02
With Secure