Analytics BIOC
Low
✕
Svchost.exe loads a rare unsigned module
Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Masquerading: Masquerade Task or Service (T1036.004) Create or Modify System Process: Windows Service (T1543.003)
Detector tags: Malicious Service Analytics
Attacker's goals:
Evading detections by running code from a signed Microsoft executable.
Investigative actions:
Check whether the loaded module with the corresponding hash is benign and if this was a desired behavior as part of its normal execution flow. Go to the 'Services' registry key and investigate its sub keys to find the service associated with the loaded dll.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day