Hi,
I got an alert "Globally rare process execution from a signed process" and after investigating the process is SynRpcServer.exe
which not uncommon and also the host uses a fingerprint sensor so it should all make sense.
But the interesting parts are on the causality chain are:
- SynRpcServer.exe executed "SynRpcServer.exe".
- The acting process is signed by Synaptics Incorporated.
- This signed vendor, image name and executed process combination is globally uncommon.
Furthermore the location of the exe is in System32 folder:
C:\Windows\System32\SynRpcServer.exeHash (of the parent
SynRpcServer.exe) 10a416072f3e581e2943f07453c5484e503c47131e48674245564030de2dd531
Any thoughts on this?