SecurityHealthService.exe

  • File Path: C:\Windows\system32\SecurityHealthService.exe
  • Description: Windows Security Health Service

Hashes

Type Hash
MD5 FCA3BAEA9E7C2251BF9D463FF8AE14CB
SHA1 ED5883F7781D7CA435D3706E605440322B31AB03
SHA256 5289A73420025011620B737D5E66198B787B6EE3D9061E1FDBD20E541F421EFF
SHA384 781A74F346574A50B415D6D411F59A3965919FAA0429472282E4BED986C878F6DEF5439B191506CB24967202B374467C
SHA512 9DFCD3E2E9E237964826E110ECB7226723033C32F7C2776EA92B12179547F1C9D880C118707739BF5CF8A7F4AFE7B7814E1D3AB97C1A66B63227C09CBA27A074
SSDEEP 24576:nq+HzDD96InKwoX6ASkHpBcnIUzAahPWkoumYH:n7RxkHdRaToumYH
IMP BB063FCC95D36207F66CFC73D31C5FB8
PESHA1 60B82F22158D4D36011ED54C012C469ED85C0B36
PE256 6C0CF66A7DBDFB9F74F64B3086194B75A529372F81098D7EEA03221EC8734B11

Runtime Data

Usage (stdout):

Unknown switch.

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SecurityHealthService.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 4.18.1907.16384 (WinBuild.160101.0800)
  • Product Version: 4.18.1907.16384
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/5289a73420025011620b737d5e66198b787b6ee3d9061e1fdbd20e541f421eff/detection/

Possible Misuse

The following table contains possible examples of SecurityHealthService.exe being misused. While SecurityHealthService.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_susp_reg_disable_sec_services.yml - '\SecurityHealthService' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.