Analytics BIOC
Informational
✕
Globally uncommon process execution from a signed process
A signed process has executed a process that, on a global level, it usually doesn't execute.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Global Anomaly Analytics
Attacker's goals:
Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.
Investigative actions:
Check if the actor process was injected or loaded a suspicious DLL before the alert. Check if the process execution and connections are legitimate.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- Globally uncommon process execution from a signed process from a known vendor Medium (parent: Informational)
- Globally rare process execution from a signed process Medium (parent: Informational)
- Globally uncommon process execution from an injected thread in a signed process Low (parent: Informational) Adds Process Injection (T1055)
- Globally uncommon process execution from a web server process or CGO Low (parent: Informational) Adds External Remote Services (T1133) Server Software Component: Web Shell (T1505.003)