Analytics BIOC Informational

Globally uncommon process execution from a signed process

A signed process has executed a process that, on a global level, it usually doesn't execute.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Detector tags: Global Anomaly Analytics
Attacker's goals:

Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.

Investigative actions:

Check if the actor process was injected or loaded a suspicious DLL before the alert. Check if the process execution and connections are legitimate.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • Globally uncommon process execution from a signed process from a known vendor Medium (parent: Informational)
  • Globally rare process execution from a signed process Medium (parent: Informational)
  • Globally uncommon process execution from an injected thread in a signed process Low (parent: Informational) Adds Process Injection (T1055)
  • Globally uncommon process execution from a web server process or CGO Low (parent: Informational) Adds External Remote Services (T1133) Server Software Component: Web Shell (T1505.003)