For the complete documentation index, see llms.txt. This page is also available as Markdown.

Execution of dllhost.exe with an empty command line

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

LOLBIN Execution Analytics

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

Low

Description

The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.

Attacker's Goals

Evade detection when running suspicious commands.

Investigative actions

  • Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

Variations

Execution of unsigned dllhost from a non-typical path with empty command line

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Masquerading: Masquerade Task or Service (T1036.004)

Severity

High

Description

An unsigned process was executed with the name dllhost.exe from a non-typical path, this behavior is suspicious and maybe performed by a malicious actor in an attempt to hide their actions.

Attacker's Goals

Evade detection when performing suspicious actions.

Investigative actions

  • Review actions performed by the executed process and the causality owner, and check if they are suspicious.

Globally uncommon execution of dllhost.exe with an empty command line

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

System Binary Proxy Execution (T1218)

Severity

Low

Description

The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.

Attacker's Goals

Evade detection when running suspicious commands.

Investigative actions

  • Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.

Was this helpful?