Suspicious module load using direct syscall
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Direct Syscall Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
Native API (T1106)
Severity
Low
Description
A module was loaded to a process using a direct syscall.
Attacker's Goals
An attacker might try to use direct syscalls to evade detection and load a malicious module to a legitimate program.
Investigative actions
Investigate the direct syscall mapped image to verify if it is malicious.
Investigate the loaded module to verify if it is malicious.
Variations
PreviousSuspicious modification of the AdminSDHolder's ACL
NextSuspicious .NET process loads an MSBuild DLL
Was this helpful?
