Analytics BIOC Low

MpCmdRun.exe was used to download files into the system

Attackers might be using legitimate Windows Defender executables to download malicious code onto the system.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Ingress Tool Transfer (T1105)
Attacker's goals:

Download malicious tools onto the host for more activities.

Investigative actions:

Check if the downloaded file is malicious. Verify if the process executing the command is malicious. Check for more suspicious actions done by the user and process.

Test period:
N/A (single event)
Deduplication:
1 Day