Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Suspicious Windows Service DLL Creation #44

Closed
FideliusFalcon opened this issue Oct 2, 2024 · 2 comments
Closed

[Bug] Suspicious Windows Service DLL Creation #44

FideliusFalcon opened this issue Oct 2, 2024 · 2 comments
Assignees
Labels
behavior Endpoint behavior issues bug Something isn't working

Comments

@FideliusFalcon
Copy link

Describe the bug
Setup.exe via DismHost.exe is triggering the "Suspicious Windows Service DLL Creation" (2c624716-75a1-42d9-bcb8-1defcb9bded9) when Windows is updating

process.executable: C:\Windows\SystemTemp\{GUID}\DismHost.exe
process.parent.executable: C:\$WINDOWS.~BT\Sources\SetupHost.exe

Desktop (please complete the following information):

  • OS: Microsoft Windows
  • Version: 11 Pro

Additional context
For now, we have seen this on:

  • Windows 11 Pro (10.0.22631.4169)
  • Windows 11 Pro (10.0.26100.1742)
@FideliusFalcon FideliusFalcon added behavior Endpoint behavior issues bug Something isn't working labels Oct 2, 2024
@joe-desimone
Copy link
Collaborator

@FideliusFalcon thank you for reporting. We have tuned the associated rule and expect the change to be released in a day or so.

@Samirbous Samirbous self-assigned this Oct 2, 2024
@Samirbous
Copy link

@FideliusFalcon thank you for reporting. The rule was updated

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
behavior Endpoint behavior issues bug Something isn't working
Projects
None yet
Development

No branches or pull requests

3 participants