Rare signature signed executable executed in the network
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
30 Days
Required Data
XDR Agent
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Subvert Trust Controls: Code Signing (T1553.002)
Severity
Informational
Description
Attackers may use signed executables by less known vendors to bypass security features.
Attacker's Goals
Adversaries may use signed binaries to bypass security features.
Investigative actions
Check if this is legitimate software installed by a legitimate user and intentionally.
Variations
Was this helpful?
