SecurityHealthService.exe
- File Path:
C:\Windows\system32\SecurityHealthService.exe
- Description: Windows Security Health Service
Hashes
Type | Hash |
---|---|
MD5 | 4F1EEF1FF02D11D9134E26478C88749A |
SHA1 | 5FD4406017DACE6C58D12F8878C59807751FDE03 |
SHA256 | 265D4D30A5998C7F38BA187300CAC868107826DC93A82E4009A887CAC26B1FEF |
SHA384 | D70B0D531472A152B8E87B4FEC8BD32EB1CA6F3579C97DD8E943638D17C905A664B0F17113006E18B75D5773C0B5D11E |
SHA512 | BA84CB221A15EFC92E443F5A5A14D5ED349C822EFC74AD9BB035FA33C35721F93FD45789956D822CBBF69CC912EB3963C01440C5A90B279995B355810371037A |
SSDEEP | 24576:mSO4f21Gdm1jBzPIrBimsmzVntc0fTum9+L:mlpdIYSnRTum9+L |
IMP | 2601842F772C1F9ABA3AAD89180D20E0 |
PESHA1 | C6A80942BBA57165B8D0491DF5069A69B17E3D74 |
PE256 | DEF0E25F9EA5C42BEF5B8820CB408EB8FF92861311C5F36CB4B7ECB45D52E6F8 |
Runtime Data
Usage (stdout):
Unknown switch.
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: SecurityHealthService.exe
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 4.18.1907.16384 (WinBuild.160101.0800)
- Product Version: 4.18.1907.16384
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/76
- VirusTotal Link: https://www.virustotal.com/gui/file/265d4d30a5998c7f38ba187300cac868107826dc93a82e4009a887cac26b1fef/detection
Possible Misuse
The following table contains possible examples of SecurityHealthService.exe
being misused. While SecurityHealthService.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | proc_creation_win_susp_reg_disable_sec_services.yml | - '\SecurityHealthService' |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.