BIOC Informational

Executable copied to remote host via admin share

An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process.

Module:
Platform Analytics
Agent event type:
File
Category:
Lateral Movement
Status:
Enabled
ATT&CK tactics: Lateral Movement (TA0008)
ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002)
Indicator:

File file path = *admin$* , *c$* AND file name = *.exe AND file path != *$NOCSC$* AND action type = write Process cgo name != perl.exe AND cgo signature = Unsigned Host host os = windows

Preventable: yes