BIOC Medium

WptsExtensions.dll created to disk

The Task Scheduler service attempts to load the missing WptsExtensions.dll. As a result, the creation of this file may be indicative of DLL hijacking.

Module:
Platform Analytics
Agent event type:
File
Category:
Privilege Escalation
Status:
Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Hijack Execution Flow: DLL (T1574.001)
Indicator:

File action type = create , read , rename , write AND file name = wptsExtensions.dll

Preventable: yes