For the complete documentation index, see llms.txt. This page is also available as Markdown.

Screensaver process executed from Users or temporary folder

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

6 Hours

Required Data

XDR Agent

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Event Triggered Execution: Screensaver (T1546.002)

Severity

Low

Description

An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators.

Attacker's Goals

Gain persistence by configuring a new screensaver.

Investigative actions

Check whether the executing process (with the SCR extension) is benign and if this was a desired behavior as part of its normal execution flow.

Variations

Screensaver process executed from Users or temporary folder by a scripting engine process

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Event Triggered Execution: Screensaver (T1546.002)

Severity

High

Description

An executable file with a screensaver extension was executed from the Users or temp folder by a scripting engine process. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators.

Attacker's Goals

Gain persistence by configuring a new screensaver.

Investigative actions

Check whether the executing process (with the SCR extension) is benign and if this was a desired behavior as part of its normal execution flow.

Was this helpful?