Globally uncommon injection from a signed process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Injection Analytics, Global Anomaly Analytics
ATT&CK Tactic
Stealth (TA0005), Persistence (TA0003)
ATT&CK Technique
System Binary Proxy Execution (T1218), Process Injection (T1055), Compromise Host Software Binary (T1554)
Severity
Informational
Description
A signed process injected into another process that it does not normally target at a global level.
Attacker's Goals
Attackers may use various methods to execute code in the context of a signed process to avoid detection.
Investigative actions
Check if the actor process loaded a suspicious DLL before the alert.
Check if the actor process was injected before the alert.
Check if the process execution and connections are legitimate.
Variations
Was this helpful?
