For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious DotNet log file created

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Reflective Code Loading (T1620), Process Injection (T1055)

Severity

Low

Description

Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files.

Attacker's Goals

Run/Inject DotNet code in the context of a signed process.

Investigative actions

  • Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.

Variations

DotNet log file created by svchost from 'Absolute software Corp' causality

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Reflective Code Loading (T1620), Process Injection (T1055)

Severity

Informational

Description

Causality 'Absolute software Corp' loads/injects into svchost and creates DotNet log files.

Attacker's Goals

Run/Inject DotNet code in the context of a signed process.

Investigative actions

  • Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.

Suspicious DotNet log file created from an injected thread

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Reflective Code Loading (T1620), Process Injection (T1055)

Severity

Low

Description

Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files.

Attacker's Goals

Run/Inject DotNet code in the context of a signed process.

Investigative actions

  • Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.

Suspicious DotNet log file created

Synopsis

Field
Value

ATT&CK Tactic

Stealth (TA0005)

ATT&CK Technique

Reflective Code Loading (T1620), Process Injection (T1055)

Severity

Low

Description

Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files.

Attacker's Goals

Run/Inject DotNet code in the context of a signed process.

Investigative actions

  • Verify if the actor process is using DotNet in a valid way.* Check if a new application was recently installed on the host at the time of the alert.

Was this helpful?