Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0311 — Detection for Spoofing Tool UI across OS Platforms
DET0311

Detection for Spoofing Tool UI across OS Platforms

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0868 Analytic 0868
Windows

Detection of inconsistencies between reported sensor health and actual process/service state. For example, Windows Defender tray icon/UI showing healthy status while corresponding Defender services (WinDefend, MsMpEng) are stopped or disabled. Correlates process creation events with missing or terminated security processes and spoofed health events.

WinEventLog:System EventCode=7036 WinEventLog:Sysmon EventCode=1
[ServiceNameList] Monitored list of critical security service names; environment-specific.
[FakeUIProcessPatterns] Patterns of filenames or paths mimicking Windows Security GUI elements.
AN0869 Analytic 0869
Linux

Monitoring for discrepancies between system daemon/service state and reported health messages (e.g., syslog shows AV/IDS daemon stopped, but spoofed messages claim it is still running). Detects userland processes impersonating AV/IDS command-line outputs or modifying log forwarding configurations.

auditd:SYSCALL execve: Execution of binaries/scripts presenting false health messages for security daemons linux:syslog Service stop or disable messages for security tools not reflected in SIEM alerts
[SecurityDaemonList] Names of AV/IDS/EDR daemons monitored in Linux environments.
AN0870 Analytic 0870
macOS

Detection of fake or spoofed macOS Security & Privacy GUIs showing healthy status after XProtect, Gatekeeper, or AV processes are disabled. Correlates user-space UI process creation with terminated or missing security daemons.

macos:unifiedlog Execution of processes mimicking Apple Security & Privacy GUIs macos:unifiedlog Termination or disabling of XProtect, Gatekeeper, or third-party AV daemons
[TrustedDaemonList] Monitored list of macOS security daemons such as XProtect, Gatekeeper, or third-party AV.

Detected Techniques

1

Details

MITRE ID
DET0311
STIX ID
x-mitre-detection-strategy--fecfb9f9-645e-4e09-ba21-05bc60722688
Analytics
3
Techniques Detected
1
By Tactic
Defense Impairment
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.