Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0366 — Detection Strategy for Double File Extension Masquerading
DET0366

Detection Strategy for Double File Extension Masquerading

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1033 Analytic 1033
Windows

Detects adversary behavior where a file with a benign-looking first extension (e.g., .txt, .jpg) ends with a dangerous second extension (e.g., .exe, .scr), and is subsequently executed. The behavior chain includes file creation with misleading naming and user or system-initiated process execution from the disguised file.

WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=11
[benign_extensions] List of extensions typically used to masquerade malicious files (.txt, .jpg, .doc, .pdf)
[dangerous_extensions] List of true executable extensions that may be abused (.exe, .scr, .hta, .lnk)
[monitored_paths] Specific directories to focus on (e.g., Downloads folder, %TEMP%, Desktop)
[TimeWindow] Duration between file creation and process execution to correlate activity
[UserContext] Whether the behavior occurs in a standard user session or elevated context

Detected Techniques

1

Details

MITRE ID
DET0366
STIX ID
x-mitre-detection-strategy--92ce4302-72cb-4b7b-9184-1fc14900d0e1
Analytics
1
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.