Analytics Low

Multiple Rare LOLBIN Process Executions by User

A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: User Execution (T1204)
Attacker's goals:

Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.

Investigative actions:

Investigate the processes that were executed to determine if they were used for legitimate purposes or malicious activity.

Test period:
1 Hour
Deduplication:
30 Days
1 variation:
  • Multiple curl process executions by user Informational (parent: Low)