MITRE ATT&CK Enterprise
T1036

Masquerading

Description

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an object, legitimate or malicious, is manipulated or abused for the sake of evading defenses and observation. This may include manipulating file metadata, tricking users into misidentifying the file type, and giving legitimate task or service names. Renaming abusable system utilities to evade security monitoring is also a form of [Masquerading](https://attack.mitre.org/techniques/T1036).(Citation: LOLBAS Main Site)

Mapped SPARTA techniques

2 techniques

  • DE-0004MasqueradingST0006
    addresses
    high

    T1036 'Masquerading' is the exact-title-and-scope ATT&CK defense-evasion technique; SPARTA DE-0004 'Masquerading' is the same activity at cross-framework level (adversary commands/components disguised as legitimate). Tactic and activity align directly.

  • DE-0012Component CollusionST0006
    relates to
    moderate

    Mapped by SPARTA, not curated by SafeMode Space.

Cite as SafeMode Space, mitre-attack-enterprise T1036.

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.