T1036.001sub-technique of T1036 Masquerading

Invalid Code Signature

macOS · Windowsnothing on this site yetT1036.001 on attack.mitre.org

Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool. Code signing provides a level of authenticity on a binary from the developer and a guarantee that the binary has not been tampered with. Adversaries can copy the metadata and signature information from a signed program, then use it as a template for an unsigned program.

MITRE ATT&CK 19.2, retrieved 2026-09-12

how MITRE says to see it

Invalid Code Signature Execution Detection via Metadata and Behavioral Context

  • Execution of binaries with invalid digital signatures, where metadata claims code is signed but validation fails. Behavior is often correlated with suspicious parent processes or unexpected execution paths.
  • Binaries or applications executed with tampered or unverifiable code signatures. Often tied to Gatekeeper bypasses, App Translocation, or use of unsigned launch daemons by untrusted users.

what reduces it

  • M1045 Code Signing. Require signed binaries.

the rest of T1036

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.