Multiple Rare LOLBIN Process Executions by User
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
30 Days
Required Data
XDR Agent
Detection Modules
Identity Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Low
Description
A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account.
Attacker's Goals
Unusual processes may be executed for various purposes, including exfiltration, lateral movement, etc.
Investigative actions
Investigate the processes that were executed to determine if they were used for legitimate purposes or malicious activity.
Variations
PreviousMultiple Okta MFA requests sent to a user
NextMultiple Rare Process Executions in Organization
Was this helpful?
