MpCmdRun.exe was used to download files into the system
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Command and Control (TA0011)
ATT&CK Technique
Ingress Tool Transfer (T1105)
Severity
Low
Description
Attackers might be using legitimate Windows Defender executables to download malicious code onto the system.
Attacker's Goals
Download malicious tools onto the host for more activities.
Investigative actions
Check if the downloaded file is malicious.
Verify if the process executing the command is malicious.
Check for more suspicious actions done by the user and process.
PreviousMount command was executed from within a Kubernetes pod to list all the attached filesystems
NextMshta.exe launched with suspicious arguments
Was this helpful?
