Globally uncommon process execution from a signed process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Global Anomaly Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Informational
Description
A signed process has executed a process that, on a global level, it usually doesn't execute.
Attacker's Goals
Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.
Investigative actions
Check if the actor process was injected or loaded a suspicious DLL before the alert.
Check if the process execution and connections are legitimate.
Variations
PreviousGlobally uncommon IP address connection from a signed process
NextGlobally uncommon root domain from a signed process
Was this helpful?
