A suspicious direct syscall was executed
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Direct Syscall Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Native API (T1106)
Severity
Low
Description
A suspicious direct syscall was executed.
Attacker's Goals
An attacker might try to use direct syscalls to evade detection from a legitimate program.
Investigative actions
Investigate the direct syscall-mapped image to verify if it is malicious.
Check if this direct syscall is part of the process execution flow.
Variations
PreviousA Successful VPN connection from TOR
NextA suspicious executable with multiple file extensions was created
Was this helpful?
