Analytics BIOC Medium

Executable created to disk by lsass.exe

Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection (T1055)
Attacker's goals:

This activity was an important stage for several exploits.

Investigative actions:

Check the file that was written to the disk for malicious activities.

Test period:
N/A (single event)
Deduplication:
6 Hours