Unusual use of a 'SysInternals' tool
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK Tactic
Stealth (TA0005)
ATT&CK Technique
Obfuscated Files or Information (T1027)
Severity
Informational
Description
An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools.
Attacker's Goals
Attackers may leverage SysInternals tools for lateral movement, credential access, or to delete recovery backups to cause impact.
Investigative actions
Check if the file is familiar to the user, if not, investigate further the source of it.
Variations
PreviousUnusual URL(s) sent by a brand were observed in the email
NextUnusual user account enablement
Was this helpful?
