Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0292 — Masquerading via Space After Filename - Behavioral Detection Strategy
DET0292

Masquerading via Space After Filename - Behavioral Detection Strategy

2 analytic(s) · 1 technique(s) detected

Analytics

2
AN0812 Analytic 0812
Linux

Detection of file execution where the file name contains a trailing space to masquerade as a known executable. Adversaries may exploit the way command line interpreters handle file names with trailing whitespace.

auditd:SYSCALL execve linux:syslog application or system execution logs
[ExecutableNameTrailingSpace] This detection may vary based on how different shells and file systems treat trailing spaces. Normalize or regex-match file names with trailing space.
[UserContext] Monitor for untrusted or lower-privileged users executing suspicious scripts with disguised names.
[TimeWindow] Tune for execution patterns during off-hours to reduce false positives.
AN0813 Analytic 0813
macOS

Execution of renamed or dropped files with a trailing space to deceive users or analysts, especially in LaunchAgents or LaunchDaemons.

macos:unifiedlog process events fs:fsusage filesystem activity
[FilenamePattern] Tunable regex or path rule to match common masquerade attempts (e.g., 'Terminal .app').
[TargetPath] Analytic can be scoped to key directories (e.g., /Users/Library/LaunchAgents/).
[UserContext] Focus detection on suspicious user sessions or service creation under non-admin users.

Detected Techniques

1

Details

MITRE ID
DET0292
STIX ID
x-mitre-detection-strategy--16462629-5b36-4bb6-a565-de4df01f75d4
Analytics
2
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.