
Rule Info
Name
Fake Document Execution
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects execution of files that contain document extensions in their name but are actually executables.
Adversaries may use this technique to masquerade malicious executables as legitimate documents to evade detection and trick users into executing them.
Date
2025-05-05 00:00:00
Modified
None
Id
75d615ec-ff0a-44c4-b421-8d99d3bd1e6a
Tags
attack.defense-evasion attack.t1036.008 attack.execution attack.t1204.002
Type
Nextron Sigma feed only (private)