For the complete documentation index, see llms.txt. This page is also available as Markdown.

Conhost.exe spawned a suspicious cmd process

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

LOLBIN Execution Analytics

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

Low

Description

Attackers may abuse the conhost process to execute malicious files and evade detection.

Attacker's Goals

Investigate the processes being spawned on the host for malicious activities.

Investigative actions

An adversary may use the conhost process to evade detection.

Variations

Conhost.exe spawned a suspicious powershell encoded command

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

High

Description

Attackers may abuse the conhost process to execute malicious files and evade detection.

Attacker's Goals

Investigate the processes being spawned on the host for malicious activities.

Investigative actions

An adversary may use the conhost process to evade detection.

Conhost.exe spawned a suspicious scripting process with long command line

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

Medium

Description

Attackers may abuse the conhost process to execute malicious files and evade detection.

Attacker's Goals

Investigate the processes being spawned on the host for malicious activities.

Investigative actions

An adversary may use the conhost process to evade detection.

Conhost.exe spawned a suspicious child process

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

Medium

Description

Attackers may abuse the conhost process to execute malicious files and evade detection.

Attacker's Goals

Investigate the processes being spawned on the host for malicious activities.

Investigative actions

An adversary may use the conhost process to evade detection.

Was this helpful?