Globally uncommon image load from a signed process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Global Anomaly Analytics, DLL Hijacking Analytics
ATT&CK Tactic
Defense Evasion (TA0005)
ATT&CK Technique
System Binary Proxy Execution (T1218), Hijack Execution Flow: DLL (T1574.001)
Severity
Informational
Description
A signed process loaded a DLL that, on a global level, it usually doesn't load.
Attacker's Goals
Attackers may use various methods to execute code in the context of a signed process to avoid detection.
Investigative actions
Check if the actor process loaded a suspicious DLL before the alert.
Check if the actor process was injected before the alert.
Check if the process execution and connections are legitimate.
Variations
PreviousGlobally uncommon high entropy process was executed
NextGlobally uncommon injection from a signed process
Was this helpful?
