Rare process running on a Linux host

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Looks for rare processes that are running on Linux hosts. Looks for process seen less than 14 times in last 7 days, or observed rate is less than 1% of of the average for the environment and fewer than 100.

Attribute Value
Type Hunting Query
Solution Syslog
ID d0ae35df-0eaf-491f-b23e-8190e4f3ffe9
Tactics Execution, Persistence
Techniques T1059, T1053, T1037
Required Connectors Syslog, SyslogAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
Syslog ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Syslog