SecurityHealthService.exe

  • File Path: C:\Windows\system32\SecurityHealthService.exe
  • Description: Windows Security Health Service

Hashes

Type Hash
MD5 4F1EEF1FF02D11D9134E26478C88749A
SHA1 5FD4406017DACE6C58D12F8878C59807751FDE03
SHA256 265D4D30A5998C7F38BA187300CAC868107826DC93A82E4009A887CAC26B1FEF
SHA384 D70B0D531472A152B8E87B4FEC8BD32EB1CA6F3579C97DD8E943638D17C905A664B0F17113006E18B75D5773C0B5D11E
SHA512 BA84CB221A15EFC92E443F5A5A14D5ED349C822EFC74AD9BB035FA33C35721F93FD45789956D822CBBF69CC912EB3963C01440C5A90B279995B355810371037A
SSDEEP 24576:mSO4f21Gdm1jBzPIrBimsmzVntc0fTum9+L:mlpdIYSnRTum9+L
IMP 2601842F772C1F9ABA3AAD89180D20E0
PESHA1 C6A80942BBA57165B8D0491DF5069A69B17E3D74
PE256 DEF0E25F9EA5C42BEF5B8820CB408EB8FF92861311C5F36CB4B7ECB45D52E6F8

Runtime Data

Usage (stdout):

Unknown switch.

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SecurityHealthService.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 4.18.1907.16384 (WinBuild.160101.0800)
  • Product Version: 4.18.1907.16384
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/76
  • VirusTotal Link: https://www.virustotal.com/gui/file/265d4d30a5998c7f38ba187300cac868107826dc93a82e4009a887cac26b1fef/detection

Possible Misuse

The following table contains possible examples of SecurityHealthService.exe being misused. While SecurityHealthService.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_reg_disable_sec_services.yml - '\SecurityHealthService' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.