BIOC
Informational
✕
Executable copied to remote host via admin share
An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Lateral Movement
- Status:
- Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002)
Indicator:
File file path = *admin$* , *c$* AND file name = *.exe AND file path != *$NOCSC$* AND action type = write Process cgo name != perl.exe AND cgo signature = Unsigned Host host os = windows
Preventable: yes