Unusual Lolbins Process Spawned by InstallUtil.exe
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
LOLBIN Execution Analytics
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
System Binary Proxy Execution: InstallUtil (T1218.004)
Severity
Low
Description
An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution.
Attacker's Goals
Gain code execution on the host.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
PreviousUnusual Kubernetes service account file read
NextUnusual multi-region AWS Resource Explorer searches
Was this helpful?
