BIOC
Informational
✕
Unsigned process injects code into a process
An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack.
- Module:
- Platform Analytics
- Agent event type:
- Remote code
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection (T1055)
Indicator:
Process action type = injection Process initiator signature = Unsigned , N/A , Invalid Signature , Weak Hash AND initiator path != *\program files* Host host os = windows
Preventable: yes