BIOC
Informational
✕
SyncAppvPublishingServer used to run PowerShell code
SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution (T1218)
Indicator:
Process action type = execution AND target process name = SyncAppvPublishingServer.exe Host host os = windows
Preventable: yes