Analytics BIOC
Low
✕
MpCmdRun.exe was used to download files into the system
Attackers might be using legitimate Windows Defender executables to download malicious code onto the system.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Command and Control (TA0011)
ATT&CK techniques: Ingress Tool Transfer (T1105)
Attacker's goals:
Download malicious tools onto the host for more activities.
Investigative actions:
Check if the downloaded file is malicious. Verify if the process executing the command is malicious. Check for more suspicious actions done by the user and process.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day