BIOC Informational

Unsigned process injects code into a process

An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack.

Module:
Platform Analytics
Agent event type:
Remote code
Category:
Execution
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection (T1055)
Indicator:

Process action type = injection Process initiator signature = Unsigned , N/A , Invalid Signature , Weak Hash AND initiator path != *\program files* Host host os = windows

Preventable: yes