For the complete documentation index, see llms.txt. This page is also available as Markdown.

Rare signature signed executable executed in the network

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

30 Days

Required Data

XDR Agent

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Subvert Trust Controls: Code Signing (T1553.002)

Severity

Informational

Description

Attackers may use signed executables by less known vendors to bypass security features.

Attacker's Goals

Adversaries may use signed binaries to bypass security features.

Investigative actions

Check if this is legitimate software installed by a legitimate user and intentionally.

Variations

Rare signature signed forensic tool remotely executed in the network

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Subvert Trust Controls: Code Signing (T1553.002)

Severity

Medium

Description

Attackers may use signed executables by less known vendors to bypass security features.

Attacker's Goals

Adversaries may use signed binaries to bypass security features.

Investigative actions

Check if this is legitimate software installed by a legitimate user and intentionally.

  • Check the capabilities of the forensic tool, for example if it can read data directly from the disk.

  • Check other activities seen from the same remote IP address.

Rare signature signed forensic tool executed in the network

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Subvert Trust Controls: Code Signing (T1553.002)

Severity

Low

Description

Attackers may use signed executables by less known vendors to bypass security features.

Attacker's Goals

Adversaries may use signed binaries to bypass security features.

Investigative actions

Check if this is legitimate software installed by a legitimate user and intentionally.

  • Check the capabilities of the forensic tool, for example if it can read data directly from the disk.

Rare signature signed executable extracted from an internet-downloaded archive and executed in the network

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Subvert Trust Controls: Code Signing (T1553.002)

Severity

Low

Description

Attackers may use signed executables by less known vendors to bypass security features.

Attacker's Goals

Adversaries may use signed binaries to bypass security features.

Investigative actions

Check if this is legitimate software installed by a legitimate user and intentionally.

Rare signature signed executable downloaded from an uncommon source and executed in the network

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Subvert Trust Controls: Code Signing (T1553.002)

Severity

Low

Description

Attackers may use signed executables by less known vendors to bypass security features.

Attacker's Goals

Adversaries may use signed binaries to bypass security features.

Investigative actions

Check if this is legitimate software installed by a legitimate user and intentionally.

Was this helpful?