Compliance Node Overview
MITRE ATT&CK T1036.005 (Match Legitimate Resource Name or Location) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by placing an executable in a commonly trusted directory (ex: under System32) or giving it the name of a legitimate, trusted program (ex: svchost.exe). In containerized environments, this may also be done by creating a resource in a namespace that matches the naming convention of a container pod or cluster. Affected platforms: Linux, macOS, Windows, Containers. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1038 Execution Prevention, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-06, CM-07, IA-09.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1036/005/
SHA-256 integrity: a0bc1d582f079a4fdeac9d112faa564641011656ef869976db8039f1db2ca809
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1036.005: Match Legitimate Resource Name or Location (https://attack.mitre.org/techniques/T1036/005/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access