SecurityHealthService.exe
- File Path:
C:\Windows\system32\SecurityHealthService.exe
- Description: Windows Security Health Service
Hashes
Type | Hash |
---|---|
MD5 | 96BE970B2CB0BB0A86D8F74C1A3F8596 |
SHA1 | 67C9150529F292FB5A2511CFBBB89E9749ECCDEE |
SHA256 | 8A33DA8CC05398C29688C5BB4D8643EE055F9E707FDBC80815CCFADAD7824C2C |
SHA384 | BC2C824900A80A24232F89FEEB95553AB3343C908CAA95DE782B26E1D81366955DC82D4E7066AF5AD4D79239FF4B0ED2 |
SHA512 | 5CBE9A06179C6BF0C9C2CAA7102982EFBB8403F69C95F9FE5ACA05391081A4364F467FD666E85BEE5215D1C7685D972A0C2E9A1AC35D3E9F4A0A45EEA177F16D |
SSDEEP | 24576:nTTDSXwRPhDsw5JJO1y79VSJ8hF1zTuad0:nB5JJO5GL1zTuad0 |
IMP | 2601842F772C1F9ABA3AAD89180D20E0 |
PESHA1 | 7C28B68B33EACBA8E72EE86385BC2EC51D989845 |
PE256 | 5578494375FFE903F57D897E6B3A76451D9D24F7BFDB704FA2CD488090B330AC |
Runtime Data
Usage (stdout):
Unknown switch.
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: SecurityHealthService.exe
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 4.18.1907.16384 (WinBuild.160101.0800)
- Product Version: 4.18.1907.16384
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/75
- VirusTotal Link: https://www.virustotal.com/gui/file/8a33da8cc05398c29688c5bb4d8643ee055f9e707fdbc80815ccfadad7824c2c/detection
Possible Misuse
The following table contains possible examples of SecurityHealthService.exe
being misused. While SecurityHealthService.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | proc_creation_win_susp_reg_disable_sec_services.yml | - '\SecurityHealthService' |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.