SecurityHealthService.exe
- File Path:
C:\Windows\system32\SecurityHealthService.exe
- Description: Windows Security Health Service
Hashes
Type | Hash |
---|---|
MD5 | FCA3BAEA9E7C2251BF9D463FF8AE14CB |
SHA1 | ED5883F7781D7CA435D3706E605440322B31AB03 |
SHA256 | 5289A73420025011620B737D5E66198B787B6EE3D9061E1FDBD20E541F421EFF |
SHA384 | 781A74F346574A50B415D6D411F59A3965919FAA0429472282E4BED986C878F6DEF5439B191506CB24967202B374467C |
SHA512 | 9DFCD3E2E9E237964826E110ECB7226723033C32F7C2776EA92B12179547F1C9D880C118707739BF5CF8A7F4AFE7B7814E1D3AB97C1A66B63227C09CBA27A074 |
SSDEEP | 24576:nq+HzDD96InKwoX6ASkHpBcnIUzAahPWkoumYH:n7RxkHdRaToumYH |
IMP | BB063FCC95D36207F66CFC73D31C5FB8 |
PESHA1 | 60B82F22158D4D36011ED54C012C469ED85C0B36 |
PE256 | 6C0CF66A7DBDFB9F74F64B3086194B75A529372F81098D7EEA03221EC8734B11 |
Runtime Data
Usage (stdout):
Unknown switch.
Signature
- Status: Signature verified.
- Serial:
330000026551AE1BBD005CBFBD000000000265
- Thumbprint:
E168609353F30FF2373157B4EB8CD519D07A2BFF
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: SecurityHealthService.exe
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 4.18.1907.16384 (WinBuild.160101.0800)
- Product Version: 4.18.1907.16384
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/68
- VirusTotal Link: https://www.virustotal.com/gui/file/5289a73420025011620b737d5e66198b787b6ee3d9061e1fdbd20e541f421eff/detection/
Possible Misuse
The following table contains possible examples of SecurityHealthService.exe
being misused. While SecurityHealthService.exe
is not inherently malicious, its legitimate functionality can be abused for malicious purposes.
Source | Source File | Example | License |
---|---|---|---|
sigma | proc_creation_win_susp_reg_disable_sec_services.yml | - '\SecurityHealthService' |
DRL 1.0 |
MIT License. Copyright (c) 2020-2021 Strontic.