What MITRE ATT&CK T1036.004: Masquerade Task or Service (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1036.004 (Masquerade Task or Service) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd will typically be given a name and/or description. Windows services will have a service name as well as a display name. Many benign tasks and services exist that have commonly associated names. Adversaries may give tasks or services names that are similar or identical to those of legitimate ones. Affected platforms: Windows, Linux, macOS. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-06, CM-07, IA-09.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1036/004/
SHA-256 integrity: e3fcbd80a4f53c534d4b8926e9a082d6f9e8d97ef04aaeba4c71ee066bb35ea7
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1036.004: Masquerade Task or Service (https://attack.mitre.org/techniques/T1036/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1036-004-masquerade-task-or-service.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1036-004-masquerade-task-or-service.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1036-004-masquerade-task-or-service
- Back to registry: Browse all 10,085 compliance nodes