Execution of dllhost.exe with an empty command line
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution (T1218)
Severity
Low
Description
The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection.
Attacker's Goals
Evade detection when running suspicious commands.
Investigative actions
Check if an entry for dllhost.exe was added in the registry, under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options.
Variations
PreviousExecution of command from within a Kubernetes pod using kubelet credentials
NextExecution of masqueraded third-party utility
Was this helpful?
