Analytics BIOC
Informational
✕
Executable moved to Windows system folder
An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Masquerading (T1036)
Detector tags: EDR Windows Disguised Processes
Attacker's goals:
An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
Investigative actions:
Check if the file is known in organization or malicious. Check if the digital signature of the file is valid and belongs to a known good software vendor. Investigate the process that has moved the file to the system folder.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Rare executable moved to Windows system folder by rare causality actor Medium (parent: Informational)
- Executable moved to Windows system folder by remote causality and a rare actor Medium (parent: Informational)
- Rare executable moved to Windows system folder by rare actor Low (parent: Informational)
- Executable moved to Windows system folder by rare and unsigned actor Low (parent: Informational)