What MITRE ATT&CK T1036.008: Masquerade File Type (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1036.008 (Masquerade File Type) is an Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file's signature, extension, and contents. Various file types have a typical standard format, including how they are encoded and organized. For example, a file's signature (also known as header or magic bytes) is the beginning bytes of a file and is often used to identify the file's type. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint, M1049 Antivirus/Antimalware, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-06, CM-07, IA-09.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1036/008/
SHA-256 integrity: a99997f7b7e87de84e9086cc053a2e73b293d76826e7848f158dedafb378e440
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1036.008: Masquerade File Type (https://attack.mitre.org/techniques/T1036/008/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access