Windows CGO, actor process and action module with anomalous characteristics
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
User Execution (T1204)
Severity
Informational
Description
Windows CGO, actor process and action module with anomalous characteristics.
Attacker's Goals
Loading modules with anomalous characteristics that commonly appear in malicious activities.
Investigative actions
Investigate the loaded image and check if it is malicious.
Investigate the CGO process and actor process that loaded the module and check if they are malicious.
Variations
PreviousWindows CGO, actor and action processes with anomalous characteristics
NextWindows Event Log was cleared using wevtutil.exe
Was this helpful?
