Suspicious process executed with a high integrity level
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
7 Days
Required Data
XDR Agent
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Abuse Elevation Control Mechanism (T1548)
Severity
Informational
Description
A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation.
Attacker's Goals
An attacker may attempt to gain higher privileges.
Investigative actions
Check whether the command line executed is benign or normal for the host and/or user performing it.
Investigate the endpoint to determine if it's a legitimate process that is supposed to run with privileges.
Variations
PreviousSuspicious process accessed certificate files
NextSuspicious process execution from tmp folder
Was this helpful?
