Executable file dropped by an unsigned service DLL
Identifies the loading of an unsigned DLL by svchost process followed by creating an executable file. Adversaries may rely on Windows Services to repeatedly execute malicious payloads as part of persistence.
- Platform: Windows
- Severity: High
- MITRE Tactic: Persistence
- MITRE Techniques: T1543, T1543.003