Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: `svchost.exe`). Alternatively, a Windows Registry key may be given a close approximation to a key used by a legitimate program. In containerized environments, a threat actor may create a resource in a trusted namespace or one that matches the naming convention of a container pod or cluster.(Citation: Aquasec Kubernetes Backdoor 2023)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Restrict File and Directory Permissions
is blocked by Execution Prevention
is blocked by Code Signing
is blocked by Detection Strategy for Masquerading via Legitimate Resource Name or Location
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Identification & Authentication for Third-Party Technology Assets, Applications and/or Services (TAAS)
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Input Data Validation
Impressum Deutsch Englisch