Execution of an uncommon process with a local/domain user SID at an early startup stage
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Generic Persistence Analytics
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Boot or Logon Autostart Execution (T1547)
Severity
Informational
Description
Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused.
Attacker's Goals
Attackers aim to get persistence to continue operating even after a reboot.
Investigative actions
Check if the CGO (causality group owner) is familiar and if any configuration, parameters, or registry keys have been modified.
Variations
PreviousExecution of an uncommon process at an early startup stage
NextExecution of an uncommon process with a local/domain user SID at early startup by a system binary
Was this helpful?
