Manipulation of netsh helper DLLs Registry keys
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
6 Hours
Required Data
XDR Agent
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Event Triggered Execution: Netsh Helper DLL (T1546.007)
Severity
Medium
Description
Registering netsh helper DLLs is uncommon, and could be used by malware for persistence.
Attacker's Goals
Command execution and persistence on the host.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
PreviousMailbox enumeration activity by Azure application
NextMasquerading as a default local account
Was this helpful?
