Analytics BIOC
Low
✕
Execution of dllhost.exe with an empty command line
The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution (T1218)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:
Evade detection when running suspicious commands.
Investigative actions:
Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Execution of unsigned dllhost from a non-typical path with empty command line High (parent: Low) Adds Masquerading: Masquerade Task or Service (T1036.004)
- Globally uncommon execution of dllhost.exe with an empty command line Low