Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Execution of dllhost.exe with an empty command line Low 2 variations

    The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Stealth (TA0005)
    ATT&CK techniques: System Binary Proxy Execution (T1218)
    Required data: XDR Agent
    Detector tags: LOLBIN Execution Analytics
    Attacker's goals: Evade detection when running suspicious commands.
    Investigative actions: Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

    Variations

    Execution of unsigned dllhost from a non-typical path with empty command line

    High overridden

    An unsigned process was executed with the name dllhost.exe from a non-typical path, this behavior is suspicious and maybe performed by a malicious actor in an attempt to hide their actions. overridden

    Globally uncommon execution of dllhost.exe with an empty command line

    Low overridden

    The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. overridden