Legitimate Process Name Used by Malware
Process "svchost.exe" detected executing from C:\Users\jdoe\AppData\Roaming\Microsoft\svchost.exe. Legitimate svchost.exe processes run exclusively from C:\Windows\System32. The file is not digitally signed and its behavior profile shows network scanning activity and credential harvesting techniques consistent with a post-exploitation framework.


