SecurityHealthService.exe

  • File Path: C:\Windows\system32\SecurityHealthService.exe
  • Description: Windows Security Health Service

Hashes

Type Hash
MD5 96BE970B2CB0BB0A86D8F74C1A3F8596
SHA1 67C9150529F292FB5A2511CFBBB89E9749ECCDEE
SHA256 8A33DA8CC05398C29688C5BB4D8643EE055F9E707FDBC80815CCFADAD7824C2C
SHA384 BC2C824900A80A24232F89FEEB95553AB3343C908CAA95DE782B26E1D81366955DC82D4E7066AF5AD4D79239FF4B0ED2
SHA512 5CBE9A06179C6BF0C9C2CAA7102982EFBB8403F69C95F9FE5ACA05391081A4364F467FD666E85BEE5215D1C7685D972A0C2E9A1AC35D3E9F4A0A45EEA177F16D
SSDEEP 24576:nTTDSXwRPhDsw5JJO1y79VSJ8hF1zTuad0:nB5JJO5GL1zTuad0
IMP 2601842F772C1F9ABA3AAD89180D20E0
PESHA1 7C28B68B33EACBA8E72EE86385BC2EC51D989845
PE256 5578494375FFE903F57D897E6B3A76451D9D24F7BFDB704FA2CD488090B330AC

Runtime Data

Usage (stdout):

Unknown switch.

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SecurityHealthService.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 4.18.1907.16384 (WinBuild.160101.0800)
  • Product Version: 4.18.1907.16384
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/75
  • VirusTotal Link: https://www.virustotal.com/gui/file/8a33da8cc05398c29688c5bb4d8643ee055f9e707fdbc80815ccfadad7824c2c/detection

Possible Misuse

The following table contains possible examples of SecurityHealthService.exe being misused. While SecurityHealthService.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_reg_disable_sec_services.yml - '\SecurityHealthService' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.