Suspicious SearchProtocolHost.exe parent process
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
6 Hours
Required Data
XDR Agent
ATT&CK Tactic
Execution (TA0002), Stealth (TA0005)
ATT&CK Technique
User Execution (T1204), System Binary Proxy Execution (T1218)
Severity
Medium
Description
SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking).
Attacker's Goals
Gain code execution on the host and evade security controls.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Was this helpful?
