Analytics BIOC Informational

Rare signature signed executable executed in the network

Attackers may use signed executables by less known vendors to bypass security features.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Subvert Trust Controls: Code Signing (T1553.002)
Attacker's goals:

Adversaries may use signed binaries to bypass security features.

Investigative actions:

Check if this is legitimate software installed by a legitimate user and intentionally.

Test period:
N/A (single event)
Deduplication:
30 Days
4 variations:
  • Rare signature signed forensic tool remotely executed in the network Medium (parent: Informational)
  • Rare signature signed forensic tool executed in the network Low (parent: Informational)
  • Rare signature signed executable extracted from an internet-downloaded archive and executed in the network Low (parent: Informational)
  • Rare signature signed executable downloaded from an uncommon source and executed in the network Low (parent: Informational)