Executable moved to Windows system folder
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
EDR Windows Disguised Processes
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036)
Severity
Informational
Description
An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
Attacker's Goals
An attacker may be trying to avoid detection by moving an executable to a Windows system folder.
Investigative actions
Check if the file is known in organization or malicious.
Check if the digital signature of the file is valid and belongs to a known good software vendor.
Investigate the process that has moved the file to the system folder.
Variations
PreviousExecutable created to disk by lsass.exe
NextExecutable or Script file written by a web server process
Was this helpful?
