BIOC Informational

SyncAppvPublishingServer used to run PowerShell code

SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: System Binary Proxy Execution (T1218)
Indicator:

Process action type = execution AND target process name = SyncAppvPublishingServer.exe Host host os = windows

Preventable: yes