For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare security product signed executable executed in the network

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Defense Evasion (TA0005)

ATT&CK Technique

Exploitation for Defense Evasion (T1211)

Severity

Low

Description

Attackers may attempt to install a security product with a known vulnerability to bypass security features.

Attacker's Goals

Adversaries may exploit the application vulnerability to bypass security features.

Investigative actions

Check if the security product was installed by a legitimate user and intentionally.

Was this helpful?