Analytics BIOC
Medium
✕
Executable created to disk by lsass.exe
Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection (T1055)
Attacker's goals:
This activity was an important stage for several exploits.
Investigative actions:
Check the file that was written to the disk for malicious activities.
- Test period:
- N/A (single event)
- Deduplication:
- 6 Hours