Globally uncommon root domain from a signed process
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Global Anomaly Analytics
ATT&CK Tactic
Stealth (TA0005), Command and Control (TA0011)
ATT&CK Technique
System Binary Proxy Execution (T1218), Application Layer Protocol (T1071)
Severity
Low
Description
A signed process connected to an external domain that, on a global level, it usually doesn't connect to.
Attacker's Goals
Attackers may use various methods to execute code in the context of a signed process to avoid detection.
Investigative actions
Check the destination domain reputation.
Check if the actor process loaded a suspicious dll before the alert.
Check if the actor process was injected before the alert.
Check if the process execution and connections are legitimate.
Variations
Was this helpful?
