BIOC Informational

Injection into ping.exe

A process injected into an instance of ping.exe.

Module:
Platform Analytics
Agent event type:
Remote code
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Process Injection (T1055)
Indicator:

Process action type = injection AND remote process name = ping.exe Process cgo name != csrss.exe AND wmiprvse.exe AND vmstoold.exe AND ctskmstr.exe AND initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Sentinel Labs, Inc. AND Dell inc. AND cgo signature = Weak Hash , Invalid Signature , N/A , Unsigned , Signed AND cgo signer != Sentinel Labs, Inc. AND Dell inc. AND initiated by != ctskmstr.exe Host host os = windows

Preventable: yes