Analytics BIOC Low

Execution of dllhost.exe with an empty command line

The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution (T1218)
Detector tags: LOLBIN Execution Analytics
Attacker's goals:

Evade detection when running suspicious commands.

Investigative actions:

Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Execution of unsigned dllhost from a non-typical path with empty command line High (parent: Low) Adds Masquerading: Masquerade Task or Service (T1036.004)
  • Globally uncommon execution of dllhost.exe with an empty command line Low