Windows CGO, actor and action processes with anomalous characteristics
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Process Anomaly Analytics
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Informational
Description
Windows CGO, actor and action processes with anomalous characteristics.
Attacker's Goals
Processes anomalous characteristics which commonly appear in malicious activities.
Investigative actions
Investigate the executed process image and check if it is malicious.
Investigate the CGO and actor processes that executed the process and check if they are malicious.
Variations
PreviousWell-known brand in sender headers with header inconsistencies
NextWindows CGO, actor process and action module with anomalous characteristics
Was this helpful?
