Suspicious Process Spawned by wininit.exe
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Masquerading (T1036)
Severity
Medium
Description
An unusual process was spawned by wininit.exe, possibly indicating malicious local or remote code execution.
Attacker's Goals
Gain code execution on the host.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Was this helpful?
