AN1560
Analytic 1560
Windows
Processes executing binaries named after legitimate system utilities (e.g., net.exe, findstr.exe, python.exe) from non-standard or application-specific directories, combined with file creation or modification events for such binaries. Defender correlates file writes in vulnerable directories, process execution paths inconsistent with baseline system paths, and abnormal parent-child relationships in process lineage.
WinEventLog:Sysmon
EventCode=11
WinEventLog:Sysmon
EventCode=15
WinEventLog:Sysmon
EventCode=1
[SuspiciousBinaryList]
Common system utilities often hijacked (e.g., net.exe, cmd.exe, powershell.exe, python.exe).
[MonitoredDirectories]
Directories where executables should not normally be written (e.g., application folders, user profile subdirs).
[TimeWindow]
Correlation window between file creation and subsequent process execution.
[ParentProcessBaseline]
Expected parent processes for critical system binaries, deviations may indicate hijacking.