Suspicious Process
- Is it a new or recognized process?
- IS the name random-looking or very short?
- Hacker use random name to prevent SOC search in EDR or SIEM
- Use a.exe to a malware
- is it running from a non-standard path?
- Most of Windows binary running from Directory : Windows\System32
- most of windows system binary and associate dll locate
- How many svchost running, what’s it?
- Lots of in Windows, host services
- If Hacker want to use svchost to name a malware, have two option
- Put it in a ono-standard path(not system32)
- Name it similar and put it in right location.
- Most of Windows binary running from Directory : Windows\System32
- Is the parent suspicious?
- Is the parent-child relationship suspicious?
- Is it tied to suspicious activity?
- Base64 encoded command-line options?
Enjoy Reading This Article?
Here are some more articles you might like to read next: