Analytics BIOC
Low
✕
Contained process execution with a rare GitHub URL
A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution: Malicious Image (T1204.003)
Attacker's goals:
Download a second stage payload for execution.
Investigative actions:
Check if the initiator process is malicious. Check the user activity on the same container at that time. Check if the container is a development container. Check if this installation was related to more installations at the same time. Check for additional file/network operations by the same process instance.
- Test period:
- N/A (single event)
- Deduplication:
- 3 Hours