I'm running into an issue where sophos flags dllhost.exe as suspicious because it runs with no command line arguments. That IS suspicious, my issue is that when I dug into it, that particular process ID it flags on my end does have a command line argument but only if I run process explorer as admin, if I run it with user rights, I see a blank command line argument. I THINK this is what is causing the false flag in sophos central.
I'm wondering if anyone else has come across this and can shed some light on it? Does sophos run with admin credentials?
BELOW IS USER
BELOW IS ADMIN
I've attached some images showing what I mean.
Thanks in advance!
Edited tags
[edited by: Gladys at 8:04 AM (GMT -7) on 27 Jun 2023]