Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapExecution of dllhost.exe with an empty command line Low 2 variations
The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Stealth (TA0005)ATT&CK techniques: System Binary Proxy Execution (T1218)Required data: XDR AgentDetector tags: LOLBIN Execution AnalyticsAttacker's goals: Evade detection when running suspicious commands.Investigative actions: Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.Variations
Execution of unsigned dllhost from a non-typical path with empty command line
High overridden
An unsigned process was executed with the name dllhost.exe from a non-typical path, this behavior is suspicious and maybe performed by a malicious actor in an attempt to hide their actions. overridden
Globally uncommon execution of dllhost.exe with an empty command line
Low overridden
The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. overridden