DeviceProcessEvents

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Process creation and related events

Attribute Value
Category MDE
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes
Azure Monitor Tables Reference View Documentation
Defender XDR Advanced Hunting Schema View Documentation

Contents

Schema (74 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AccountDomain string Domain of the account.
AccountName string User name of the account.
AccountObjectId string Unique identifier for the account in Azure AD.
AccountSid string Security Identifier (SID) of the account.
AccountUpn string User principal name (UPN) of the account.
ActionType string Type of activity that triggered the event.
AdditionalFields dynamic Additional information about the entity or event.
AppGuardContainerId string Identifier for the virtualized container used by Application Guard to isolate browser activity.
CreatedProcessSessionId long Windows session ID of the created process.
DeviceId string Unique identifier for the device in the service.
DeviceName string Fully qualified domain name (FQDN) of the device.
FileName string Name of the file that the recorded action was applied to.
FileSize long Size of the file in bytes.
FolderPath string Folder containing the file that the recorded action was applied to.
InitiatingProcessAccountDomain string Domain of the account that ran the process responsible for the event.
InitiatingProcessAccountName string User name of the account that ran the process responsible for the event.
InitiatingProcessAccountObjectId string Azure AD object ID of the user account that ran the process responsible for the event.
InitiatingProcessAccountSid string Security Identifier (SID) of the account that ran the process responsible for the event.
InitiatingProcessAccountUpn string User principal name (UPN) of the account that ran the process responsible for the event.
InitiatingProcessCommandLine string Command line used to run the process that initiated the event.
InitiatingProcessCreationTime datetime Date and time when the process that initiated the event was started.
InitiatingProcessFileName string Name of the process that initiated the event.
InitiatingProcessFileSize long The size of the file (bytes) that ran the process responsible for the event.
InitiatingProcessFolderPath string Folder containing the process (image file) that initiated the event.
InitiatingProcessId long Process ID (PID) of the process that initiated the event.
InitiatingProcessIntegrityLevel string Integrity level of the process that initiated the event. Windows assigns integrity levels to processes based on certain characteristics, such as if they were launched from an internet download. These integrity levels influence permissions to resources..
InitiatingProcessLogonId long Identifier for a logon session of the process that initiated the event. This identifier is unique on the same machine only between restarts..
InitiatingProcessMD5 string MD5 hash of the process (image file) that initiated the event.
InitiatingProcessParentCreationTime datetime Date and time when the parent of the process responsible for the event was started.
InitiatingProcessParentFileName string Name of the parent process that spawned the process responsible for the event.
InitiatingProcessParentId long Process ID (PID) of the parent process that spawned the process responsible for the event.
InitiatingProcessRemoteSessionDeviceName string Device name of the remote device from which the initiating process's RDP session was initiated.
InitiatingProcessRemoteSessionIP string IP address of the remote device from which the initiating process's RDP session was initiated.
InitiatingProcessSessionId long Windows session ID of the initiating process.
InitiatingProcessSHA1 string SHA-1 hash of the process (image file) that initiated the event.
InitiatingProcessSHA256 string SHA-256 hash of the process (image file) that initiated the event. In some cases this column may not be populated - please use the InitiatingProcessSHA1 column instead.
InitiatingProcessSignatureStatus string Information about the signature status of the process (image file) that initiated the event.
InitiatingProcessSignerType string Type of file signer of the process (image file) that initiated the event.
InitiatingProcessTokenElevation string Token type indicating the presence or absence of User Access Control (UAC) privilege elevation applied to the process that initiated the event.
InitiatingProcessUniqueId string Unique identifier of the initiating process; this is equal to the Process Start Key in Windows devices.
InitiatingProcessVersionInfoCompanyName string The company name in version information (image file) responsible for the event.
InitiatingProcessVersionInfoFileDescription string The description in version information (image file) responsible for the event.
InitiatingProcessVersionInfoInternalFileName string The internal file name in version information (image file) responsible for the event.
InitiatingProcessVersionInfoOriginalFileName string The original file name in version information (image file) responsible for the event.
InitiatingProcessVersionInfoProductName string The product name in version information (image file) responsible for the event.
InitiatingProcessVersionInfoProductVersion string The product version in version information (image file) responsible for the event.
IsInitiatingProcessRemoteSession bool Indicates whether the initiating process was run under a remote desktop protocol (RDP) session (true) or locally (false).
IsProcessRemoteSession bool Indicates whether the created process was run under a remote desktop protocol (RDP) session (true) or locally (false).
LogonId long Identifier for a logon session. This identifier is unique on the same machine only between restarts.
MachineGroup string Machine group of the machine. This group is used by role-based access control to determine access to the machine.
MD5 string MD5 hash of the file that the recorded action was applied to.
ProcessCommandLine string Command line used to create the new process.
ProcessCreationTime datetime Date and time the process was created.
ProcessId long Process ID (PID) of the newly created process.
ProcessIntegrityLevel string Integrity level of the newly created process. Windows assigns integrity levels to processes based on certain characteristics, such as if they were launched from an internet downloaded. These integrity levels influence permissions to resources..
ProcessRemoteSessionDeviceName string Device name of the remote device from which the created process's RDP session was initiated.
ProcessRemoteSessionIP string IP address of the remote device from which the created process's RDP session was initiated.
ProcessTokenElevation string Token type indicating the presence or absence of User Access Control (UAC) privilege elevation applied to the newly created process.
ProcessUniqueId string Unique identifier of the process; this is equal to the Process Start Key in Windows devices.
ProcessVersionInfoCompanyName string Company name from the version information of the newly created process.
ProcessVersionInfoFileDescription string Description from the version information of the newly created process.
ProcessVersionInfoInternalFileName string Internal file name from the version information of the newly created process.
ProcessVersionInfoOriginalFileName string Original file name from the version information of the newly created process.
ProcessVersionInfoProductName string Product name from the version information of the newly created process.
ProcessVersionInfoProductVersion string Product version from the version information of the newly created process.
ReportId long Event identifier based on a repeating counter. To identify unique events, this column must be used in conjunction with the ComputerName and EventTime columns..
SHA1 string SHA-1 hash of the file that the recorded action was applied to.
SHA256 string SHA-256 of the file that the recorded action was applied to.
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Date and time the event was recorded by the MDE agent on the endpoint.
Type string The name of the table

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (15)

This table is used by the following solutions:

Connectors (1)

This table is ingested by the following connectors:

Connector Selection Criteria
Microsoft Defender XDR

Content Items Using This Table (371)

Analytic Rules (51)

In solution Attacker Tools Threat Protection Essentials:

Analytic Rule Selection Criteria
PowerShell Encoded Command Execution (Living off the Land)
Probable AdFind Recon Tool Usage

In solution Dev 0270 Detection and Hunting:

Analytic Rule Selection Criteria
DEV-0270 New User Creation
Dev-0270 Malicious Powershell usage
Dev-0270 Registry IOC - September 2022
Dev-0270 WMIC Discovery

In solution Endpoint Threat Protection Essentials:

Analytic Rule Selection Criteria
CertUtil Used for File Download (Living off the Land)

In solution FalconFriday:

Analytic Rule Selection Criteria
Access Token Manipulation - Create Process with Token
DCOM Lateral Movement ActionType != "ListeningConnectionCreated"
InitiatingProcessParentFileName == "svchost.exe"
Detecting UAC bypass - ChangePK and SLUI registry tampering InitiatingProcessFileName == "changepk.exe"
InitiatingProcessParentFileName == "slui.exe"
ProcessIntegrityLevel == "High"
Detecting UAC bypass - elevated COM interface InitiatingProcessCommandLine has_any "E9495B87-D950-4AB5-87A5-FF6D70BF3E90"
InitiatingProcessFileName == "dllhost.exe"
ProcessIntegrityLevel == "High"
Detecting UAC bypass - modify Windows Store settings InitiatingProcessFileName == "wsreset.exe"
ProcessIntegrityLevel == "High"
Disable or Modify Windows Defender InitiatingProcessVersionInfoProductName != "Android Studio"
Ingress Tool Transfer - Certutil ProcessCommandLine has "certutil"
Match Legitimate Name or Location - 2
Oracle suspicious command execution InitiatingProcessFileName == "oracle.exe"
Remote Desktop Protocol - SharpRDP ActionType == "LogonSuccess"
Rename System Utilities
SMB/Windows Admin Shares ActionType == "InboundConnectionAccepted"
ProcessCommandLine != "msiexec.exe /V"
Suspicious parentprocess relationship - Office child processes.
Trusted Developer Utilities Proxy Execution FolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
InitiatingProcessFileName in "WDExpress.exe,devenv.exe"
InitiatingProcessFolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
ProcessCommandLine has_any "/exe"
ProcessCommandLine has_any "out"

In solution Microsoft Defender XDR:

Analytic Rule Selection Criteria
Account Creation InitiatingProcessFileName == "net.exe"
ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "/domain"
Bitsadmin Activity ProcessCommandLine has "/Upload"
ProcessCommandLine has_any "/Transfer"
Clearing of forensic evidence from event logs using wevtutil ProcessCommandLine has "CL"
ProcessCommandLine has "WEVTUTIL"
Deletion of data on multiple drives using cipher exe ProcessCommandLine has "/w"
Detect Suspicious Commands Initiated by Webserver Processes InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessFileName startswith "tomcat"
InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine contains "%temp%"
ProcessCommandLine has "certutil"
ProcessCommandLine has "ipconfig"
ProcessCommandLine has "ping"
ProcessCommandLine has "systeminfo"
ProcessCommandLine has "timeout"
ProcessCommandLine has "wget"
ProcessCommandLine has "whoami"
Disabling Security Services via Registry
Doppelpaymer Stop Services InitiatingProcessFileName startswith "psexe"
ProcessCommandLine has "msexchange"
ProcessCommandLine has "sql"
ProcessCommandLine has "stop-service"
DopplePaymer Procdump ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
Execution of software vulnerable to webp buffer overflow of CVE-2023-4863
Java Executing cmd to run Powershell InitiatingProcessFileName == "java.exe"
LSASS Credential Dumping with Procdump ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
ProcessCommandLine has "lsass.exe"
LaZagne Credential Theft
Office Apps Launching Wscipt InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"
ProcessCommandLine has ".jse"
Potential Build Process Compromise - MDE ActionType in "FileCreated,FileModified"
Qakbot Campaign Self Deletion InitiatingProcessCommandLine has "-n 6"
InitiatingProcessCommandLine has "127.0.0.1"
InitiatingProcessCommandLine has "calc.exe"
InitiatingProcessFileName == "cmd.exe"
Qakbot Discovery Activies InitiatingProcessCommandLine endswith "127.0.0.1"
InitiatingProcessCommandLine has "-a"
InitiatingProcessCommandLine has "-nao"
InitiatingProcessCommandLine has "-t"
InitiatingProcessCommandLine has "/all"
InitiatingProcessFileName in "explorer.exe,mobsync.exe"
Rare Process as a Service
Regsvr32 Rundll32 with Anomalous Parent Process
Shadow Copy Deletions
Stopping multiple processes using taskkill

In solution Windows Security Events:

Analytic Rule Selection Criteria
WMI Spawning Suspicious Child Process (Living off the Land)

In solution Zinc Open Source:

Analytic Rule Selection Criteria
Zinc Actor IOCs files - October 2022
[Deprecated] - Zinc Actor IOCs domains hashes IPs and useragent - October 2022

Standalone Content:

Analytic Rule Selection Criteria
Audit policy manipulation using auditpol utility InitiatingProcessFileName == "auditpol.exe"
Dev-0228 File Path Hashes November 2021
Email access via active sync
Identify Mango Sandstorm powershell commands
SUNBURST suspicious SolarWinds child processes InitiatingProcessFileName == "solarwinds.businesslayerhost.exe"
Security Service Registry ACL Modification
Unusual identity creation using exchange powershell

Hunting Queries (312)

In solution Cyware: ProcessCommandLine has "powershell.exe"

Hunting Query
Detecting Suspicious PowerShell Command Executions

In solution Endpoint Threat Protection Essentials:

Hunting Query Selection Criteria
Backup Deletion
Potential Microsoft Security Services Tampering InitiatingProcessCommandLine has "$true"
InitiatingProcessCommandLine has "/IM"
InitiatingProcessCommandLine has "Set-MpPreference"
InitiatingProcessCommandLine has "Start"
InitiatingProcessCommandLine has "config"
InitiatingProcessParentFileName != "cscript.exe"
Rare Windows Firewall Rule updates using Netsh InitiatingProcessCommandLine has_all "advfirewall"
InitiatingProcessFileName == "netsh.exe"
Unicode Obfuscation in Command Line

In solution Hybrid Attack - Cloud & Identity:

Hunting Query Selection Criteria
Cloud Run Command followed by kernel persistence indicators on target servers

In solution Legacy IOC based Threat Protection:

Hunting Query Selection Criteria
Dev-0056 Command Line Activity November 2021
Dev-0322 Command Line Activity November 2021 InitiatingProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"
ProcessCommandLine matchesregex "cmd.exe /c"
ProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"
Dev-0322 File Drop Activity November 2021
Nylon Typhoon Command Line Activity November 2021
SolarWinds Inventory

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Account Creation InitiatingProcessFileName == "net.exe"
ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "/domain"
Anomalous Payload Delivered from ISO files ActionType == "BrowserLaunchedToOpenUrl"
Bitsadmin Activity ProcessCommandLine has "/Upload"
ProcessCommandLine has_any "/Transfer"
Check for multiple signs of Ransomware Activity ProcessCommandLine has "cl"
ProcessCommandLine has "config"
ProcessCommandLine has "delete"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
ProcessCommandLine has "wbadmin"
ProcessCommandLine has "wevtutil"
ProcessCommandLine has "wmic"
Clear System Logs ProcessCommandLine has "deletejournal"
ProcessCommandLine has "usn"
Clearing of forensic evidence from event logs using wevtutil ProcessCommandLine has "CL"
ProcessCommandLine has "WEVTUTIL"
Credential Harvesting Using LaZagne ProcessCommandLine has "hklm"
ProcessCommandLine has "sam"
ProcessCommandLine has "save"
DLLHost.exe WMIC domain discovery InitiatingProcessCommandLine == "dllhost.exe"
InitiatingProcessFileName == "dllhost.exe"
ProcessCommandLine has "wmic computersystem get domain"
Deletion of data on multiple drives using cipher exe ProcessCommandLine has "/w"
Detect MaiSniper
Detect Malicious use of Msiexec Mimikatz InitiatingProcessFileName == "msiexec.exe"
ProcessCommandLine contains "privilege::"
ProcessCommandLine contains "token::"
ProcessCommandLine has "sekurlsa"
Detect Suspicious Commands Initiated by Webserver Processes InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessFileName startswith "tomcat"
InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine contains "%temp%"
ProcessCommandLine has "certutil"
ProcessCommandLine has "ipconfig"
ProcessCommandLine has "ping"
ProcessCommandLine has "systeminfo"
ProcessCommandLine has "timeout"
ProcessCommandLine has "wget"
ProcessCommandLine has "whoami"
Detect Suspicious Mshta Usage InitiatingProcessCommandLine contains "<script>"
InitiatingProcessFileName == "mshta.exe"
Disabling Services via Registry
Doppelpaymer Stop Services InitiatingProcessFileName startswith "psexe"
ProcessCommandLine has "msexchange"
ProcessCommandLine has "sql"
ProcessCommandLine has "stop-service"
DopplePaymer Procdump ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
Enumeration of Users & Groups for Lateral Movement ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "\\"
ProcessCommandLine contains "/do"
ProcessCommandLine contains "/domain"
ProcessCommandLine contains "group"
ProcessCommandLine contains "user"
Imminent Ransomware
Java Executing cmd to run Powershell InitiatingProcessFileName == "java.exe"
Judgement Panda Exfil Activity
LaZagne Credential Theft
MITRE - Suspicious Events
Malicious Use of MSBuild as LOLBin InitiatingProcessFileName == "wmiprvse.exe"
ProcessCommandLine has "programdata"
Office Apps Launching Wscipt InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"
ProcessCommandLine has ".jse"
Possible Teams phishing activity
PowerShell Downloads ProcessCommandLine has "DownloadFile"
ProcessCommandLine has "IEX"
ProcessCommandLine has "Invoke-Shellcode"
ProcessCommandLine has "Invoke-WebRequest"
ProcessCommandLine has "Net.WebClient"
ProcessCommandLine has "Start-BitsTransfer"
ProcessCommandLine has "http"
ProcessCommandLine has "mpcmdrun.exe"
PowerShell adding exclusion path for Microsoft Defender of ProgramData
Qakbot Campaign Self Deletion InitiatingProcessCommandLine has "-n 6"
InitiatingProcessCommandLine has "127.0.0.1"
InitiatingProcessCommandLine has "calc.exe"
InitiatingProcessFileName == "cmd.exe"
Qakbot Discovery Activies InitiatingProcessCommandLine endswith "127.0.0.1"
InitiatingProcessCommandLine has "-a"
InitiatingProcessCommandLine has "-nao"
InitiatingProcessCommandLine has "-t"
InitiatingProcessCommandLine has "/all"
InitiatingProcessFileName in "explorer.exe,mobsync.exe"
Qakbot Reconnaissance Activities ProcessCommandLine has_any "whoami /all"
Rare Process as a Service
Regsvr32 Rundll32 with Anomalous Parent Process
Shadow Copy Deletions
Spoolsv Spawning Rundll32 InitiatingProcessCommandLine endswith "rundll32.exe"
InitiatingProcessFileName == "rundll32.exe"
InitiatingProcessParentFileName has "spoolsv.exe"
Stopping multiple processes using taskkill
Suspicious Tomcat Confluence Process Launch InitiatingProcessCommandLine has "confluence"
Turning off services using sc exe ProcessCommandLine has "config"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
Webserver Executing Suspicious Applications InitiatingProcessFileName in "httpd.exe,w3wp.exe"

In solution MicrosoftDefenderForEndpoint:

Hunting Query Selection Criteria
Probable AdFind Recon Tool Usage

Standalone Content:

Hunting Query Selection Criteria
BadUSB HID injection PowerShell via Windows Run dialog InitiatingProcessFileName == "explorer.exe"
ProcessCommandLine has_all "-ExecutionPolicy"
ProcessCommandLine has_all "-WindowStyle"
List all the VScode Extensions which are installed on a user system ProcessCommandLine contains "VSIxs"
ProcessCommandLine contains "vsce-sign.exe"
MDE_FindsPowerShellExecutionEvents ProcessCommandLine has "DownloadFile"
ProcessCommandLine has "Invoke-Shellcode"
ProcessCommandLine has "Invoke-WebRequest"
ProcessCommandLine has "Net.WebClient"
ProcessCommandLine has "http:"
SUNBURST suspicious SolarWinds child processes InitiatingProcessFileName == "solarwinds.businesslayerhost.exe"

GitHub Only:

Hunting Query Selection Criteria
7-zip-prep-for-exfiltration ProcessCommandLine contains "ProgramData\\pst"
APT Baby Shark ProcessCommandLine == "cmd.exe /c taskkill /im cmd.exe"
ProcessCommandLine startswith "powershell.exe mshta.exe http"
APT29 thinktanks ProcessCommandLine has "-noni -ep bypass $"
Abuse.ch Recent Threat Feed
Abuse.ch Recent Threat Feed (1)
Accessibility Features
Add malicious user to Admins and RDP users group via PowerShell InitiatingProcessFileName == "powershell.exe"
AppLocker Policy Design Assistant FolderPath !startswith "/"
Backup deletion ProcessCommandLine has "delete"
ProcessCommandLine has "shadowcopy"
BadUSB LOLBIN execution via certutil (HID injection via Run dialog) InitiatingProcessFileName == "explorer.exe"
ProcessCommandLine has "certutil"
Base64 Detector and Decoder
Base64encodePEFile ProcessCommandLine contains "TVqQAAMAAAAEAAA"
Baseline Comparison
Bear Activity GTR 2019
Bitsadmin Activity ProcessCommandLine has "/Upload"
ProcessCommandLine has_any "/Transfer"
CVE-2021-36934 usage detection AccountName != "system"
ProcessCommandLine contains "HKLM"
Check for multiple signs of ransomware activity ProcessCommandLine has "cl"
ProcessCommandLine has "config"
ProcessCommandLine has "delete"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
ProcessCommandLine has "wbadmin"
ProcessCommandLine has "wevtutil"
ProcessCommandLine has "wmic"
Clearing of forensic evidence from event logs using wevtutil ProcessCommandLine has "CL"
ProcessCommandLine has "WEVTUTIL"
Cloud Hopper ProcessCommandLine has ".vbs /shell"
Crashing Applications
Create account InitiatingProcessFileName == "net.exe"
ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "/domain"
Create new user with known DEV-0270 username and password
Critical user management operations followed by disabling of System Restore from admin account InitiatingProcessFileName == "rundll32.exe"
ProcessCommandLine has "Change"
ProcessCommandLine has "SystemRestore"
ProcessCommandLine has "disable"
DLLHost.exe WMIC domain discovery InitiatingProcessCommandLine == "dllhost.exe"
InitiatingProcessFileName == "dllhost.exe"
ProcessCommandLine has "wmic computersystem get domain"
DLLHost.exe file creation via PowerShell InitiatingProcessFileName == "powershell.exe"
DarkSide
Deletion of data on multiple drives using cipher exe ProcessCommandLine has "/w"
Detect Encoded Powershell
Detect Malicious use of MSIExec ProcessCommandLine has "http"
ProcessCommandLine has "return"
Disable Controlled Folders InitiatingProcessFileName == "cmd.exe"
Disabling Services via Registry
Discovering potentially tampered devices [Nobelium]
Discovery for highly-privileged accounts
Dopplepaymer In-Memory Malware Implant ProcessCommandLine contains "}} -p"
ProcessCommandLine startswith "-q -s {{"
Dragon Fly
Electron-CVE-2018-1000006 InitiatingProcessFileName in "chrome.exe,iexplore.exe,runtimebroker.exe"
ProcessCommandLine has "--gpu-launcher"
Elise backdoor
Email data exfiltration via PowerShell
EmojiHunt
Enumeration of users & groups for lateral movement ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "\\"
ProcessCommandLine contains "/do"
ProcessCommandLine contains "/domain"
ProcessCommandLine contains "group"
ProcessCommandLine contains "user"
Equation Group C2 Communication ProcessCommandLine endswith ",dll_u"
ProcessCommandLine has "-export dll_u"
Excel Macro Execution InitiatingProcessFileName == "excel.exe"
Excel launching anomalous processes InitiatingProcessFileName in "excel.exe,regsvr32.exe"
InitiatingProcessParentFileName has "excel.exe"
ExecuteBase64DecodedPayload ProcessCommandLine contains ".b64decode("
ProcessCommandLine contains ".decode("
ProcessCommandLine contains ".decode64("
ProcessCommandLine contains "base64 --decode"
HostExportingMailboxAndRemovingExport[Solarigate] ProcessCommandLine contains "New-MailboxExportRequest"
ProcessCommandLine contains "Remove-MailboxExportRequest"
Hunt for RMM tool execution following Teams messages
Hunt for RMM tool execution following Teams messages
Hurricane Panda activity ProcessCommandLine endswith "localgroup administrators admin /add"
Identify unusual identity additions related to EUROPIUM ProcessCommandLine has "HealthMailbox55x2yq"
ProcessCommandLine has_any "New-Mailbox"
Imminent Ransomware
Inhibit recovery by disabling tools and functionality ProcessCommandLine has "REG_DWORD /d \"
ProcessCommandLine has_all "reg"
Judgement Panda exfil activity
LSASS Credential Dumping with Procdump ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
ProcessCommandLine has "lsass.exe"
LaZagne Credential Theft
LemonDuck-competition-killer
LemonDuck-component-download-structure InitiatingProcessFileName == "cmd.exe"
LemonDuck-component-names InitiatingProcessFileName == "cmd.exe"
LemonDuck-defender-exclusions InitiatingProcessCommandLine has_all "Set-MpPreference"
Linux-DynoRoot-CVE-2018-1111 InitiatingProcessCommandLine contains "-dhclient"
InitiatingProcessCommandLine contains "/etc/NetworkManager/dispatcher.d/"
MITRE - Suspicious Events
MacOceanLotusBackdoor
MacOceanLotusDropper ProcessCommandLine contains "theme0"
Make FolderPath Vogon Poetry
Malware_In_recyclebin ProcessCommandLine contains ":\\recycler"
Masquerading system executable
Mass account password change
Modifying the registry to add a ransom message notification
NTDS theft ProcessCommandLine has_any "temp"
PSExec Attrib commands InitiatingProcessCommandLine has ".bat"
InitiatingProcessParentFileName endswith "PSEXESVC.exe"
Password Protected Archive Creation
Possible Ransomware Related Destruction Activity ProcessCommandLine contains "/grant Everyone:F"
ProcessCommandLine contains "/w"
ProcessCommandLine has "/all"
ProcessCommandLine has "/change"
ProcessCommandLine has "/d"
ProcessCommandLine has "/disable"
ProcessCommandLine has "/quiet"
ProcessCommandLine has "delete shadows"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
Possible Teams phishing activity
Possible command injection attempts against Azure Integration Runtimes
PotentialMicrosoftDefenderTampering[Solarigate] InitiatingProcessCommandLine has "$true"
InitiatingProcessCommandLine has "/IM"
InitiatingProcessCommandLine has "/d 1"
InitiatingProcessCommandLine has "Set-MpPreference"
InitiatingProcessCommandLine has "config"
InitiatingProcessParentFileName != "cscript.exe"
PowerShell adding exclusion path for Microsoft Defender of ProgramData
PowerShell downloads ProcessCommandLine has "DownloadFile"
ProcessCommandLine has "IEX"
ProcessCommandLine has "Invoke-Shellcode"
ProcessCommandLine has "Invoke-WebRequest"
ProcessCommandLine has "Net.WebClient"
ProcessCommandLine has "Start-BitsTransfer"
ProcessCommandLine has "http"
ProcessCommandLine has "mpcmdrun.exe"
Qakbot discovery activies InitiatingProcessCommandLine endswith "127.0.0.1"
InitiatingProcessCommandLine has "-a"
InitiatingProcessCommandLine has "-nao"
InitiatingProcessCommandLine has "-t"
InitiatingProcessCommandLine has "/all"
InitiatingProcessFileName in "explorer.exe,mobsync.exe"
Qakbot reconnaissance activities ProcessCommandLine has_any "whoami /all"
Ransomware hits healthcare - Alternate Data Streams use ProcessCommandLine has "-p"
ProcessCommandLine startswith "-q -s"
Ransomware hits healthcare - Cipher.exe tool deleting data ProcessCommandLine has "/w"
Ransomware hits healthcare - Clearing of system logs ProcessCommandLine has "deletejournal"
ProcessCommandLine has "usn"
Ransomware hits healthcare - Robbinhood activity InitiatingProcessFileName == "winlogon.exe"
Ransomware hits healthcare - Turning off System Restore InitiatingProcessFileName == "rundll32.exe"
ProcessCommandLine has "Change"
ProcessCommandLine has "SystemRestore"
ProcessCommandLine has "disable"
Rare firewall rule changes using netsh InitiatingProcessCommandLine has_all "advfirewall"
InitiatingProcessFileName == "netsh.exe"
Rare-process-as-a-service
RedMenshen-BPFDoor-backdoor InitiatingProcessCommandLine has "/dev/shm/kdmtmpflush"
Remote Management and Monitoring tool - AeroAdmin - Create Process ProcessVersionInfoCompanyName has_any "AeroAdmin"
ProcessVersionInfoProductName has_any "AeroAdmin"
Remote Management and Monitoring tool - Ammyy - Create Process ProcessVersionInfoCompanyName has "Ammyy"
ProcessVersionInfoProductName has "Ammyy Admin"
Remote Management and Monitoring tool - AnyDesk - Create Process ProcessVersionInfoCompanyName has_any "anydesk software"
ProcessVersionInfoProductName has "anydesk"
Remote Management and Monitoring tool - AnyViewer - Create Process ProcessVersionInfoCompanyName has "AOMEI"
ProcessVersionInfoProductName has "AnyViewer"
Remote Management and Monitoring tool - Atera - Create Process ProcessVersionInfoCompanyName has "Atera Networks"
Remote Management and Monitoring tool - AweSun - Create Process ProcessVersionInfoCompanyName has "AweRay"
ProcessVersionInfoProductName has "AweSun"
Remote Management and Monitoring tool - BarracudaRMM - Create Process ProcessVersionInfoCompanyName has_any "Barracuda MSP"
Remote Management and Monitoring tool - BeyondTrust - Create Process ProcessVersionInfoCompanyName has_any "BeyondTrust"
Remote Management and Monitoring tool - ChromeRDP - Create Process ProcessVersionInfoCompanyName has "Google"
ProcessVersionInfoProductName has "Chrome Remote Desktop"
Remote Management and Monitoring tool - ConnectWise - Create Process ProcessVersionInfoCompanyName has_any "ConnectWise"
Remote Management and Monitoring tool - DameWare - Create Process ProcessVersionInfoCompanyName has_any "DameWare"
ProcessVersionInfoFileDescription has "DameWare"
ProcessVersionInfoProductName has "DameWare"
Remote Management and Monitoring tool - DesktopNow - Create Process ProcessVersionInfoCompanyName has "NCH Software"
ProcessVersionInfoProductName has "DesktopNow"
Remote Management and Monitoring tool - DistantDesktop - Create Process ProcessVersionInfoCompanyName has "Distant Software"
ProcessVersionInfoProductName has "Distant Desktop"
Remote Management and Monitoring tool - FleetDeck - Create Process ProcessVersionInfoCompanyName has "FleetDeck"
ProcessVersionInfoProductName has "FleetDeck"
Remote Management and Monitoring tool - GetScreen - Create Process ProcessVersionInfoCompanyName has "getscreen.me"
ProcessVersionInfoProductName has "getscreen.me"
Remote Management and Monitoring tool - ISLOnline - Create Process ProcessVersionInfoCompanyName has_any "Xlab"
ProcessVersionInfoProductName has_any "ISL Light"
Remote Management and Monitoring tool - IperiusRemote - Create Process ProcessVersionInfoCompanyName has "Enter Srl"
ProcessVersionInfoProductName has "Iperius Remote"
Remote Management and Monitoring tool - Level - Create Process
Remote Management and Monitoring tool - LiteManager - Create Process ProcessVersionInfoProductName has_any "LiteManager"
Remote Management and Monitoring tool - LogMeIn - Create Process ProcessVersionInfoCompanyName has "LogMeIn"
ProcessVersionInfoProductName has_any "LogMeIn"
Remote Management and Monitoring tool - MSP360_CloudBerry - Create Process ProcessVersionInfoCompanyName has_any "CloudBerry"
ProcessVersionInfoProductName has_any "RMM"
Remote Management and Monitoring tool - MeshCentral - Create Process ProcessVersionInfoProductName has "meshcentral"
Remote Management and Monitoring tool - NAble - Create Process ProcessVersionInfoCompanyName has_any "N-Able"
Remote Management and Monitoring tool - Naverisk - Create Process ProcessVersionInfoCompanyName has_any "naverisk"
Remote Management and Monitoring tool - NetSupport - Create Process ProcessVersionInfoCompanyName has "netsupport"
Remote Management and Monitoring tool - NinjaRMM - Create Process ProcessVersionInfoCompanyName has_any "NinjaRMM"
ProcessVersionInfoProductName has "NinjaRMM"
Remote Management and Monitoring tool - OptiTune - Create Process ProcessVersionInfoCompanyName has "Bravura Software LLC"
ProcessVersionInfoProductName has "OptiTune"
Remote Management and Monitoring tool - PDQ - Create Process ProcessVersionInfoProductName has "PDQConnectAgent"
Remote Management and Monitoring tool - Panorama9 - Create Process ProcessVersionInfoCompanyName has "panorama9"
ProcessVersionInfoProductName has "panorama9"
Remote Management and Monitoring tool - PcVisit - Create Process ProcessVersionInfoCompanyName has "pcvisit software ag"
ProcessVersionInfoProductName has "pcvisit"
Remote Management and Monitoring tool - Pulseway - Create Process ProcessVersionInfoCompanyName has "MMSoft Design"
ProcessVersionInfoProductName has "Pulseway"
Remote Management and Monitoring tool - RPort - Create Process ProcessVersionInfoCompanyName has "RealVNC"
ProcessVersionInfoProductName has "rport"
Remote Management and Monitoring tool - RealVNC - Create Process ProcessVersionInfoCompanyName has "realvnc"
Remote Management and Monitoring tool - RemoteDesktopPlus - Create Process ProcessVersionInfoCompanyName has "www.donkz.nl"
ProcessVersionInfoOriginalFileName has "rdp.exe"
ProcessVersionInfoProductName has "Remote Desktop Plus"
Remote Management and Monitoring tool - RemotePC - Create Process ProcessVersionInfoCompanyName has "idrive"
ProcessVersionInfoProductName has_any "remotepc"
Remote Management and Monitoring tool - RemoteUtilities - Create Process ProcessVersionInfoCompanyName has "Remote Utilities"
ProcessVersionInfoProductName has "Remote Utilities"
Remote Management and Monitoring tool - RustDesk - Create Process ProcessVersionInfoProductName has "rustdesk"
Remote Management and Monitoring tool - ScreenMeet - Create Process ProcessVersionInfoCompanyName has "Projector Inc"
ProcessVersionInfoProductName has "ScreenMeet"
Remote Management and Monitoring tool - ServerEye - Create Process ProcessVersionInfoCompanyName has "Krämer IT Solutions GmbH"
ProcessVersionInfoProductName has_any "ServerEye"
Remote Management and Monitoring tool - ShowMyPC - Create Process ProcessVersionInfoCompanyName has "ShowMyPC"
ProcessVersionInfoProductName has "ShowMyPC"
Remote Management and Monitoring tool - SimpleHelp - Create Process ProcessVersionInfoCompanyName has "SimpleHelp"
ProcessVersionInfoProductName has "SimpleHelp"
Remote Management and Monitoring tool - Splashtop - Create Process ProcessVersionInfoCompanyName has "Splashtop"
ProcessVersionInfoProductName has "Splashtop"
Remote Management and Monitoring tool - SupRemo - Create Process ProcessVersionInfoCompanyName has "NanoSystems"
ProcessVersionInfoProductName has "SupRemo"
Remote Management and Monitoring tool - SyncroMSP - Create Process ProcessVersionInfoCompanyName has "Servably, Inc."
ProcessVersionInfoProductName has "Syncro"
Remote Management and Monitoring tool - TacticalRMM - Create Process ProcessVersionInfoCompanyName has_any "AmidaWare"
ProcessVersionInfoProductName has "Tactical RMM"
Remote Management and Monitoring tool - TeamViewer - Create Process ProcessVersionInfoCompanyName has "TeamViewer"
ProcessVersionInfoProductName has "TeamViewer"
Remote Management and Monitoring tool - TigerVNC - Create Process ProcessVersionInfoCompanyName has "TigerVNC"
ProcessVersionInfoProductName has "TigerVNC"
Remote Management and Monitoring tool - TightVNC - Create Process ProcessVersionInfoCompanyName has "GlavSoft"
ProcessVersionInfoProductName has "TightVNC"
Remote Management and Monitoring tool - UltraViewer - Create Process ProcessVersionInfoCompanyName has "DucFabulous"
ProcessVersionInfoProductName has "UltraViewer"
Remote Management and Monitoring tool - XMReality - Create Process ProcessVersionInfoCompanyName has "XMReality"
ProcessVersionInfoProductName has "XMReality"
Remote Management and Monitoring tool - ZohoAssist - Create Process ProcessVersionInfoCompanyName has "Zoho"
ProcessVersionInfoProductName has "Zoho Assist"
Remote Management and Monitoring tool - mRemoteNG - Create Process ProcessVersionInfoProductName has "mRemoteNG"
Remote Management and Monitoring tool - parsec.app - Create Process ProcessVersionInfoCompanyName has "Parsec"
ProcessVersionInfoProductName has "Parsec"
Remote Management and Montioring tool - Action1 - Create Process ProcessVersionInfoCompanyName has "Action1"
ProcessVersionInfoProductName has "Action1"
Renamed Rclone Exfil ProcessVersionInfoProductName has "rclone"
Shadow Copy Deletions
Spoolsv Spawning Rundll32 InitiatingProcessCommandLine endswith "rundll32.exe"
InitiatingProcessFileName == "rundll32.exe"
InitiatingProcessParentFileName has "spoolsv.exe"
Stolen Images Execution
Stopping multiple processes using taskkill
Stopping processes using net stop ProcessCommandLine has "stop"
StrRAT-AV-Discovery InitiatingProcessCommandLine has "roaming"
InitiatingProcessFileName in "java.exe,javaw.exe"
ProcessCommandLine has "path antivirusproduct get displayname"
StrRAT-Malware-Persistence InitiatingProcessFileName in "java.exe,javaw.exe"
Suspicious Bitlocker Encryption ProcessCommandLine contains "1"
ProcessCommandLine has "EnableBDEWithNoTPM"
ProcessCommandLine has "true"
Suspicious JScript staging comment ProcessCommandLine has "VMBlastSG"
Suspicious PowerShell curl flags
Suspicious Tomcat Confluence Process Launch InitiatingProcessCommandLine has "confluence"
Suspicious process event creation from VMWare Horizon TomcatService InitiatingProcessFileName has "ws_TomcatService.exe"
SuspiciousEnumerationUsingAdfind[Nobelium] ProcessCommandLine matchesregex "(.*)>(.*)"
Turning off System Restore InitiatingProcessFileName == "rundll32.exe"
ProcessCommandLine has "Change"
ProcessCommandLine has "SystemRestore"
ProcessCommandLine has "disable"
Turning off services using sc exe ProcessCommandLine has "config"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
Use of MSBuild as LOLBin InitiatingProcessFileName == "wmiprvse.exe"
ProcessCommandLine has "programdata"
VMWare-LPE-2022-22960 InitiatingProcessCommandLine has_any "/opt/vmware/certproxy/bing/certproxyService.sh"
WastedLocker Downloader InitiatingProcessFileName == "wscript.exe"
Webserver Executing Suspicious Applications InitiatingProcessFileName in "httpd.exe,w3wp.exe"
Zip-Doc - Word Launching MSHTA InitiatingProcessFileName == "WINWORD.EXE"
alt-data-streams ProcessCommandLine startswith "-q -s"
anomalous-payload-delivered-from-iso-file ActionType == "BrowserLaunchedToOpenUrl"
app-armor-stopped InitiatingProcessCommandLine has "/bin/bash /tmp/"
ProcessCommandLine has "service apparmor stop"
apt sofacy
apt sofacy zebrocy ProcessCommandLine endswith "cmd.exe /c SYSTEMINFO & TASKLIST"
apt ta17 293a ps ProcessCommandLine == "ps.exe -accepteula"
apt tropictrooper ProcessCommandLine contains "abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc"
apt unidentified nov 18 ProcessCommandLine endswith "cyzfc.dat, PointFunctionCall"
check-for-shadowhammer-activity-implant
clear-system-logs ProcessCommandLine has "deletejournal"
ProcessCommandLine has "usn"
cobalt-strike-invoked-w-wmi InitiatingProcessFileName == "wmiprvse.exe"
ProcessCommandLine !has "Windows\\CCM\\"
ProcessCommandLine contains "frombase64"
ProcessCommandLine matchesregex "[A-Za-z0-9+/]{50,}[=]{0,2}"
confluence-weblogic-targeted InitiatingProcessCommandLine contains "//confluence"
InitiatingProcessFileName == "beasvc.exe"
InitiatingProcessParentFileName == "beasvc.exe"
ProcessCommandLine !contains "ApplicationNo"
ProcessCommandLine !contains "Cosmos"
ProcessCommandLine !contains "CustomerGroup"
ProcessCommandLine !contains "Unrestricted"
ProcessCommandLine !startswith "POWERSHELL.EXE -C \"
ProcessCommandLine contains "$"
ProcessCommandLine contains "-e"
ProcessCommandLine contains "-split"
ProcessCommandLine contains ">"
ProcessCommandLine contains "@echo"
ProcessCommandLine contains "encodedcommand"
ProcessCommandLine contains "wget"
cve-2019-0808-set-scheduled-task ProcessCommandLine contains "ecosetup"
ProcessCommandLine contains "highest"
ProcessCommandLine contains "spsextserv.exe"
cypherpunk-exclusive-commands InitiatingProcessParentFileName startswith "psexe"
ProcessCommandLine has "Dvr /go"
cypherpunk-remote-exec-w-psexesvc InitiatingProcessCommandLine has ".bat"
InitiatingProcessParentFileName startswith "psexe"
ProcessCommandLine has "DisableIOAVProtection"
deleting-data-w-cipher-tool ProcessCommandLine has "/w"
detect-anomalous-process-trees
detect-cve-2019-0863-AngryPolarBearBug2-exploit ProcessCommandLine contains "/run"
ProcessCommandLine contains "Windows Error Reporting"
detect-cve-2019-0973-installerbypass-exploit ProcessCommandLine contains "/fa"
ProcessCommandLine contains ":\\windows\\installer"
detect-cve-2019-1129-byebear-exploit ProcessCommandLine contains "del"
ProcessCommandLine contains "rmdir"
detect-cyzfc-activity (2) ProcessCommandLine contains "-noni -ep bypass $zk="
detect-cyzfc-activity (3) ProcessCommandLine contains "https://www.jmj.com/personal/nauerthn_state_gov"
detect-doublepulsar-execution ProcessCommandLine contains "payload"
ProcessCommandLine contains "targetip"
ProcessCommandLine contains "targetport"
ProcessCommandLine contains "verifybackdoor"
detect-exploitation-of-cve-2018-8653 InitiatingProcessCommandLine contains "WinHttpAutoProxySvc"
InitiatingProcessFileName == "svchost.exe"
detect-impacket-atexec ActionType in "NamedPipeEvent,RegistryKeyCreated"
detect-impacket-dcomexec ActionType == "InboundConnectionAccepted"
detect-impacket-psexec-module ActionType == "FileCreated"
detect-impacket-wmiexec
detect-impacket-wmiexec
detect-impacket-wmiexec
detect-mailsniper
detect-malicious-rar-extraction
detect-malicious-use-of-msiexec ProcessCommandLine has "http"
ProcessCommandLine has "return"
detect-malicious-use-of-msiexec-mimikatz InitiatingProcessFileName == "msiexec.exe"
ProcessCommandLine contains "privilege::"
ProcessCommandLine contains "token::"
ProcessCommandLine has "sekurlsa"
detect-malicious-use-of-msiexec-powershell ProcessCommandLine contains "%temp%"
detect-nbtscan-activity
detect-office-applications-spawning-msdt-CVE-2022-30190 InitiatingProcessFileName in "excel.exe,outlook.exe,powerpnt.exe,winword.exe"
detect-office-products-spawning-wmic InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"
detect-prifou-pua ProcessCommandLine has "/mds"
ProcessCommandLine has "/mhp"
ProcessCommandLine has "/mnl"
ProcessCommandLine has "/mnt"
ProcessCommandLine has "bundlename=chromium"
ProcessCommandLine has "rsf"
detect-steganography-exfiltration
detect-suspicious-commands-initiated-by-web-server-processes InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessFileName startswith "tomcat"
InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine contains "%temp%"
ProcessCommandLine has "certutil"
ProcessCommandLine has "ipconfig"
ProcessCommandLine has "ping"
ProcessCommandLine has "systeminfo"
ProcessCommandLine has "timeout"
ProcessCommandLine has "wget"
ProcessCommandLine has "whoami"
detect-suspicious-mshta-usage InitiatingProcessCommandLine contains "<script>"
InitiatingProcessFileName == "mshta.exe"
detect-uac-elevation ProcessTokenElevation == "TokenElevationTypeFull"
detect-web-server-exploit-doublepulsar InitiatingProcessCommandLine contains "//confluence"
InitiatingProcessFileName == "beasvc.exe"
InitiatingProcessParentFileName == "beasvc.exe"
ProcessCommandLine !contains "ApplicationNo"
ProcessCommandLine !contains "Cosmos"
ProcessCommandLine !contains "CustomerGroup"
ProcessCommandLine !contains "Unrestricted"
ProcessCommandLine !startswith "POWERSHELL.EXE -C \"
ProcessCommandLine contains "$"
ProcessCommandLine contains "-e"
ProcessCommandLine contains "-split"
ProcessCommandLine contains ">"
ProcessCommandLine contains "@echo"
ProcessCommandLine contains "encodedcommand"
ProcessCommandLine contains "wget"
doppelpaymer
doppelpaymer-procdump ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
doppelpaymer-psexec InitiatingProcessFileName startswith "psexe"
doppelpaymer-stop-services InitiatingProcessFileName startswith "psexe"
ProcessCommandLine has "msexchange"
ProcessCommandLine has "sql"
ProcessCommandLine has "stop-service"
evasive-powershell-executions ProcessCommandLine has_all "-command"
evasive-powershell-strings
exchange-powershell-snapin-loaded ProcessCommandLine contains "Add-PSSnapin Microsoft.Exchange.Powershell.Snapin"
hiding-java-class-file ProcessCommandLine contains ".class"
ProcessCommandLine has "attrib +h +s +r"
insider-threat-detection-queries (13)
insider-threat-detection-queries (14)
insider-threat-detection-queries (2)
insider-threat-detection-queries (3)
insider-threat-detection-queries (8)
java-executing-cmd-to-run-powershell InitiatingProcessFileName == "java.exe"
jse-launched-by-word InitiatingProcessFileName in "explorer.exe,winword.exe"
ProcessCommandLine contains ".jse"
kinsing-miner-download
launch-questd-w-osascript ProcessCommandLine contains "questd"
ProcessCommandLine has "osascript -e do shell script \"
launching-base64-powershell[Nobelium] InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe"
launching-cmd-echo[Nobelium] InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe"
ProcessCommandLine has "echo"
lazagne ProcessCommandLine has "hklm"
ProcessCommandLine has "sam"
ProcessCommandLine has "save"
locate-shlayer-payload-decryption-activity ProcessCommandLine has "-base64"
ProcessCommandLine has "-nosalt"
ProcessCommandLine has "-out"
locate-shlayer-payload-decrytion-activity ProcessCommandLine has "-base64"
ProcessCommandLine has "-nosalt"
ProcessCommandLine has "-out"
locate-surfbuyer-downloader-decoding-activity ProcessCommandLine has "/tmp/e_"
ProcessCommandLine has "base64"
oceanlotus-apt32-files
office-apps-launching-wscipt InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"
ProcessCommandLine has ".jse"
oracle-webLogic-executing-powershell
powercat-download ProcessCommandLine endswith "powercat.ps1"
powershell-activity-after-email-from-malicious-sender InitiatingProcessParentFileName == "outlook.exe"
powershell-version-2.0-execution ProcessCommandLine has "-v 2"
ProcessCommandLine has "-v 2.0"
ProcessCommandLine has "-version 2"
ProcessCommandLine has "-version 2.0"
procdump-lsass-credentials ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
ProcessCommandLine has "lsass.exe"
python-based-attacks-on-macos InitiatingProcessParentFileName in "Microsoft Excel,Microsoft Word"
ProcessCommandLine matchesregex "[A-Za-z0-9]{50}"
python-use-by-ransomware-macos ProcessCommandLine contains "EIKKEIKK"
ProcessCommandLine contains "python"
qakbot-campaign-esentutl ProcessCommandLine has "WebCache"
ProcessCommandLine has_any "V01"
qakbot-campaign-process-injection ProcessCommandLine has "WebCache"
ProcessCommandLine has_any "V01"
qakbot-campaign-self-deletion InitiatingProcessCommandLine has "-n 6"
InitiatingProcessCommandLine has "127.0.0.1"
InitiatingProcessCommandLine has "calc.exe"
InitiatingProcessFileName == "cmd.exe"
qakbot-campaign-suspicious-javascript InitiatingProcessCommandLine has "start /MIN"
InitiatingProcessFileName == "cmd.exe"
ProcessCommandLine has "E:javascript"
ransom-note-creation-macos ProcessCommandLine has "say \\\"
rare_sch_task_with_activity
rce-on-vulnerable-server InitiatingProcessCommandLine has "php-cgi.exe"
ProcessCommandLine has_all "curl -fsSL"
regsvr32-rundll32-with-anomalous-parent-process
reverse-shell-nishang ProcessCommandLine contains "$client = New-Object System.Net.Sockets.TCPClient"
reverse-shell-nishang-base64 ProcessCommandLine contains "-e"
reverse-shell-ransomware-macos ProcessCommandLine has "bash -i >& /dev/tcp/"
robbinhood-evasion InitiatingProcessFileName == "winlogon.exe"
shimcache-flushed ProcessCommandLine has_any "apphelp.dll"
sql-server-abuse InitiatingProcessFileName in "launchpad.exe,sqlagent.exe,sqlps.exe,sqlservr.exe"
tomcat-8-executing-powershell InitiatingProcessFileName in "cmd.exe,powershell.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine has_any "cmd.exe"
turn-off-system-restore InitiatingProcessFileName == "rundll32.exe"
ProcessCommandLine has "Change"
ProcessCommandLine has "SystemRestore"
ProcessCommandLine has "disable"
umworkerprocess-unusual-subprocess-activity InitiatingProcessFileName == "UMWorkerProcess.exe"
wadhrama-data-destruction ProcessCommandLine has "delete"
ProcessCommandLine has "shadowcopy"
wadhrama-ransomware
wdigest-caching ProcessCommandLine has "1"
ProcessCommandLine has "UseLogonCredential"
ProcessCommandLine has "WDigest"
ProcessCommandLine has "dword"
wifikeys ProcessCommandLine has "key=clear"
ProcessCommandLine startswith "netsh"

Workbooks (8)

In solution HIPAA Compliance: ProcessCommandLine has "Set-MpPreference"

Workbook
HIPAACompliance

In solution Lumen Defender Threat Feed:

Workbook Selection Criteria
Lumen-Threat-Feed-Overview

In solution MaturityModelForEventLogManagementM2131: ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"

Workbook
MaturityModelForEventLogManagement_M2131

In solution Microsoft Defender XDR:

Workbook Selection Criteria
MicrosoftDefenderForEndPoint

GitHub Only:

Workbook Selection Criteria
MicrosoftDefenderForEndPoint
MicrosoftSentinelDeploymentandMigrationTracker
SolarWindsPostCompromiseHunting ActionType == "RemoteInteractiveLogon"
ActionType == "LdapSearch"
WorkspaceUsage

Parsers Using This Table (1)

ASIM Parsers (1)

Parser Schema Product Selection Criteria
ASimProcessEventMicrosoft365D ProcessEvent Microsoft 365 Defender for endpoint

Selection Criteria Summary (200 criteria, 256 total references)

References by type: 0 connectors, 256 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
ProcessCommandLine has "/w" - 5 - - 5
InitiatingProcessFileName == "rundll32.exe"
ProcessCommandLine has "Change"
ProcessCommandLine has "SystemRestore"
ProcessCommandLine has "disable"
- 4 - - 4
ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
- 3 - - 3
ProcessCommandLine contains "-ma"
ProcessCommandLine has "-accepteula"
ProcessCommandLine has "lsass"
ProcessCommandLine has "lsass.exe"
- 3 - - 3
InitiatingProcessFileName startswith "psexe"
ProcessCommandLine has "msexchange"
ProcessCommandLine has "sql"
ProcessCommandLine has "stop-service"
- 3 - - 3
InitiatingProcessCommandLine has "-n 6"
InitiatingProcessCommandLine has "127.0.0.1"
InitiatingProcessCommandLine has "calc.exe"
InitiatingProcessFileName == "cmd.exe"
- 3 - - 3
InitiatingProcessFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessFileName startswith "tomcat"
InitiatingProcessParentFileName in "beasvc.exe,httpd.exe,w3wp.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine contains "%temp%"
ProcessCommandLine has "certutil"
ProcessCommandLine has "ipconfig"
ProcessCommandLine has "ping"
ProcessCommandLine has "systeminfo"
ProcessCommandLine has "timeout"
ProcessCommandLine has "wget"
ProcessCommandLine has "whoami"
- 3 - - 3
ProcessCommandLine has "/Upload"
ProcessCommandLine has_any "/Transfer"
- 3 - - 3
InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe"
ProcessCommandLine has ".jse"
- 3 - - 3
InitiatingProcessFileName == "net.exe"
ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "/domain"
- 3 - - 3
ProcessCommandLine has "CL"
ProcessCommandLine has "WEVTUTIL"
- 3 - - 3
InitiatingProcessCommandLine endswith "127.0.0.1"
InitiatingProcessCommandLine has "-a"
InitiatingProcessCommandLine has "-nao"
InitiatingProcessCommandLine has "-t"
InitiatingProcessCommandLine has "/all"
InitiatingProcessFileName in "explorer.exe,mobsync.exe"
- 3 - - 3
InitiatingProcessFileName == "java.exe" - 3 - - 3
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "usn"
- 3 - - 3
InitiatingProcessFileName == "cmd.exe" - 3 - - 3
InitiatingProcessFileName == "solarwinds.businesslayerhost.exe" - 2 - - 2
InitiatingProcessCommandLine has_all "advfirewall"
InitiatingProcessFileName == "netsh.exe"
- 2 - - 2
ProcessCommandLine has "hklm"
ProcessCommandLine has "sam"
ProcessCommandLine has "save"
- 2 - - 2
ProcessCommandLine !contains "/add"
ProcessCommandLine !contains "\\"
ProcessCommandLine contains "/do"
ProcessCommandLine contains "/domain"
ProcessCommandLine contains "group"
ProcessCommandLine contains "user"
- 2 - - 2
ActionType == "BrowserLaunchedToOpenUrl" - 2 - - 2
ProcessCommandLine has "http"
ProcessCommandLine has "return"
- 2 - - 2
InitiatingProcessFileName == "msiexec.exe"
ProcessCommandLine contains "privilege::"
ProcessCommandLine contains "token::"
ProcessCommandLine has "sekurlsa"
- 2 - - 2
ProcessCommandLine has "DownloadFile"
ProcessCommandLine has "IEX"
ProcessCommandLine has "Invoke-Shellcode"
ProcessCommandLine has "Invoke-WebRequest"
ProcessCommandLine has "Net.WebClient"
ProcessCommandLine has "Start-BitsTransfer"
ProcessCommandLine has "http"
ProcessCommandLine has "mpcmdrun.exe"
- 2 - - 2
InitiatingProcessFileName in "httpd.exe,w3wp.exe" - 2 - - 2
InitiatingProcessCommandLine contains "<script>"
InitiatingProcessFileName == "mshta.exe"
- 2 - - 2
InitiatingProcessCommandLine has "confluence" - 2 - - 2
ProcessCommandLine has "cl"
ProcessCommandLine has "config"
ProcessCommandLine has "delete"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
ProcessCommandLine has "wbadmin"
ProcessCommandLine has "wevtutil"
ProcessCommandLine has "wmic"
- 2 - - 2
ProcessCommandLine has "config"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
- 2 - - 2
InitiatingProcessCommandLine == "dllhost.exe"
InitiatingProcessFileName == "dllhost.exe"
ProcessCommandLine has "wmic computersystem get domain"
- 2 - - 2
InitiatingProcessCommandLine endswith "rundll32.exe"
InitiatingProcessFileName == "rundll32.exe"
InitiatingProcessParentFileName has "spoolsv.exe"
- 2 - - 2
InitiatingProcessFileName == "wmiprvse.exe"
ProcessCommandLine has "programdata"
- 2 - - 2
ProcessCommandLine has_any "whoami /all" - 2 - - 2
InitiatingProcessCommandLine contains "//confluence"
InitiatingProcessFileName == "beasvc.exe"
InitiatingProcessParentFileName == "beasvc.exe"
ProcessCommandLine !contains "ApplicationNo"
ProcessCommandLine !contains "Cosmos"
ProcessCommandLine !contains "CustomerGroup"
ProcessCommandLine !contains "Unrestricted"
ProcessCommandLine !startswith "POWERSHELL.EXE -C \"
ProcessCommandLine contains "$"
ProcessCommandLine contains "-e"
ProcessCommandLine contains "-split"
ProcessCommandLine contains ">"
ProcessCommandLine contains "@echo"
ProcessCommandLine contains "encodedcommand"
ProcessCommandLine contains "wget"
- 2 - - 2
InitiatingProcessFileName == "winlogon.exe" - 2 - - 2
ProcessCommandLine has "WebCache"
ProcessCommandLine has_any "V01"
- 2 - - 2
ProcessCommandLine has "-base64"
ProcessCommandLine has "-nosalt"
ProcessCommandLine has "-out"
- 2 - - 2
ProcessCommandLine has "delete"
ProcessCommandLine has "shadowcopy"
- 2 - - 2
InitiatingProcessFileName == "powershell.exe" - 2 - - 2
ProcessCommandLine has "certutil" - 1 - - 1
ActionType != "ListeningConnectionCreated"
InitiatingProcessParentFileName == "svchost.exe"
- 1 - - 1
InitiatingProcessVersionInfoProductName != "Android Studio" - 1 - - 1
InitiatingProcessFileName == "oracle.exe" - 1 - - 1
ActionType == "LogonSuccess" - 1 - - 1
ActionType == "InboundConnectionAccepted"
ProcessCommandLine != "msiexec.exe /V"
- 1 - - 1
FolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
InitiatingProcessFileName in "WDExpress.exe,devenv.exe"
InitiatingProcessFolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
ProcessCommandLine has_any "/exe"
ProcessCommandLine has_any "out"
- 1 - - 1
InitiatingProcessCommandLine has_any "E9495B87-D950-4AB5-87A5-FF6D70BF3E90"
InitiatingProcessFileName == "dllhost.exe"
ProcessIntegrityLevel == "High"
- 1 - - 1
InitiatingProcessFileName == "wsreset.exe"
ProcessIntegrityLevel == "High"
- 1 - - 1
InitiatingProcessFileName == "changepk.exe"
InitiatingProcessParentFileName == "slui.exe"
ProcessIntegrityLevel == "High"
- 1 - - 1
ActionType in "FileCreated,FileModified" - 1 - - 1
InitiatingProcessFileName == "auditpol.exe" - 1 - - 1
ProcessCommandLine has "powershell.exe" - 1 - - 1
InitiatingProcessCommandLine has "$true"
InitiatingProcessCommandLine has "/IM"
InitiatingProcessCommandLine has "Set-MpPreference"
InitiatingProcessCommandLine has "Start"
InitiatingProcessCommandLine has "config"
InitiatingProcessParentFileName != "cscript.exe"
- 1 - - 1
InitiatingProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"
ProcessCommandLine matchesregex "cmd.exe /c"
ProcessCommandLine matchesregex "save HKLM\\SYSTEM [^ ]*_System.HIV"
- 1 - - 1
InitiatingProcessFileName == "explorer.exe"
ProcessCommandLine has_all "-ExecutionPolicy"
ProcessCommandLine has_all "-WindowStyle"
- 1 - - 1
ProcessCommandLine contains "VSIxs"
ProcessCommandLine contains "vsce-sign.exe"
- 1 - - 1
InitiatingProcessFileName == "explorer.exe"
ProcessCommandLine has "certutil"
- 1 - - 1
ProcessCommandLine == "cmd.exe /c taskkill /im cmd.exe"
ProcessCommandLine startswith "powershell.exe mshta.exe http"
- 1 - - 1
ProcessCommandLine endswith "cmd.exe /c SYSTEMINFO & TASKLIST" - 1 - - 1
ProcessCommandLine == "ps.exe -accepteula" - 1 - - 1
ProcessCommandLine contains "abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc" - 1 - - 1
ProcessCommandLine endswith "cyzfc.dat, PointFunctionCall" - 1 - - 1
ProcessCommandLine has "-noni -ep bypass $" - 1 - - 1
ProcessCommandLine has ".vbs /shell" - 1 - - 1
InitiatingProcessFileName == "wmiprvse.exe"
ProcessCommandLine !has "Windows\\CCM\\"
ProcessCommandLine contains "frombase64"
ProcessCommandLine matchesregex "[A-Za-z0-9+/]{50,}[=]{0,2}"
- 1 - - 1
InitiatingProcessParentFileName startswith "psexe"
ProcessCommandLine has "Dvr /go"
- 1 - - 1
InitiatingProcessCommandLine has ".bat"
InitiatingProcessParentFileName startswith "psexe"
ProcessCommandLine has "DisableIOAVProtection"
- 1 - - 1
ProcessCommandLine contains "-noni -ep bypass $zk=" - 1 - - 1
ProcessCommandLine contains "https://www.jmj.com/personal/nauerthn_state_gov" - 1 - - 1
ProcessCommandLine contains "}} -p"
ProcessCommandLine startswith "-q -s {{"
- 1 - - 1
ProcessCommandLine endswith ",dll_u"
ProcessCommandLine has "-export dll_u"
- 1 - - 1
ProcessCommandLine endswith "localgroup administrators admin /add" - 1 - - 1
InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe" - 1 - - 1
InitiatingProcessFileName == "SolarWinds.BusinessLayerHost.exe"
ProcessCommandLine has "echo"
- 1 - - 1
ProcessCommandLine contains "theme0" - 1 - - 1
ProcessCommandLine has "-p"
ProcessCommandLine startswith "-q -s"
- 1 - - 1
InitiatingProcessCommandLine has "/dev/shm/kdmtmpflush" - 1 - - 1
InitiatingProcessFileName == "wscript.exe" - 1 - - 1
ProcessCommandLine contains "New-MailboxExportRequest"
ProcessCommandLine contains "Remove-MailboxExportRequest"
- 1 - - 1
ProcessCommandLine contains "EIKKEIKK"
ProcessCommandLine contains "python"
- 1 - - 1
ProcessCommandLine has "bash -i >& /dev/tcp/" - 1 - - 1
ProcessCommandLine has "1"
ProcessCommandLine has "UseLogonCredential"
ProcessCommandLine has "WDigest"
ProcessCommandLine has "dword"
- 1 - - 1
ProcessCommandLine startswith "-q -s" - 1 - - 1
ProcessCommandLine contains ".class"
ProcessCommandLine has "attrib +h +s +r"
- 1 - - 1
InitiatingProcessCommandLine has "$true"
InitiatingProcessCommandLine has "/IM"
InitiatingProcessCommandLine has "/d 1"
InitiatingProcessCommandLine has "Set-MpPreference"
InitiatingProcessCommandLine has "config"
InitiatingProcessParentFileName != "cscript.exe"
- 1 - - 1
ProcessCommandLine has_any "apphelp.dll" - 1 - - 1
ProcessCommandLine endswith "powercat.ps1" - 1 - - 1
ProcessCommandLine has "DownloadFile"
ProcessCommandLine has "Invoke-Shellcode"
ProcessCommandLine has "Invoke-WebRequest"
ProcessCommandLine has "Net.WebClient"
ProcessCommandLine has "http:"
- 1 - - 1
ProcessCommandLine matchesregex "(.*)>(.*)" - 1 - - 1
ProcessCommandLine contains "TVqQAAMAAAAEAAA" - 1 - - 1
ProcessCommandLine contains "payload"
ProcessCommandLine contains "targetip"
ProcessCommandLine contains "targetport"
ProcessCommandLine contains "verifybackdoor"
- 1 - - 1
InitiatingProcessCommandLine contains "WinHttpAutoProxySvc"
InitiatingProcessFileName == "svchost.exe"
- 1 - - 1
ActionType in "NamedPipeEvent,RegistryKeyCreated" - 1 - - 1
ActionType == "InboundConnectionAccepted" - 1 - - 1
ActionType == "FileCreated" - 1 - - 1
ProcessCommandLine contains "%temp%" - 1 - - 1
InitiatingProcessFileName in "excel.exe,outlook.exe,powerpnt.exe,winword.exe" - 1 - - 1
InitiatingProcessFileName in "excel.exe,outlook.exe,winword.exe" - 1 - - 1
ProcessCommandLine contains ".b64decode("
ProcessCommandLine contains ".decode("
ProcessCommandLine contains ".decode64("
ProcessCommandLine contains "base64 --decode"
- 1 - - 1
InitiatingProcessFileName in "explorer.exe,winword.exe"
ProcessCommandLine contains ".jse"
- 1 - - 1
ProcessCommandLine contains "questd"
ProcessCommandLine has "osascript -e do shell script \"
- 1 - - 1
ProcessCommandLine has "/tmp/e_"
ProcessCommandLine has "base64"
- 1 - - 1
ProcessCommandLine contains ":\\recycler" - 1 - - 1
ProcessCommandLine contains "/grant Everyone:F"
ProcessCommandLine contains "/w"
ProcessCommandLine has "/all"
ProcessCommandLine has "/change"
ProcessCommandLine has "/d"
ProcessCommandLine has "/disable"
ProcessCommandLine has "/quiet"
ProcessCommandLine has "delete shadows"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
- 1 - - 1
InitiatingProcessParentFileName == "outlook.exe" - 1 - - 1
ProcessCommandLine has "-v 2"
ProcessCommandLine has "-v 2.0"
ProcessCommandLine has "-version 2"
ProcessCommandLine has "-version 2.0"
- 1 - - 1
InitiatingProcessParentFileName in "Microsoft Excel,Microsoft Word"
ProcessCommandLine matchesregex "[A-Za-z0-9]{50}"
- 1 - - 1
InitiatingProcessCommandLine has "start /MIN"
InitiatingProcessFileName == "cmd.exe"
ProcessCommandLine has "E:javascript"
- 1 - - 1
ProcessCommandLine contains "-e" - 1 - - 1
ProcessCommandLine contains "$client = New-Object System.Net.Sockets.TCPClient" - 1 - - 1
InitiatingProcessFileName in "launchpad.exe,sqlagent.exe,sqlps.exe,sqlservr.exe" - 1 - - 1
InitiatingProcessFileName == "UMWorkerProcess.exe" - 1 - - 1
ProcessCommandLine contains "ProgramData\\pst" - 1 - - 1
ProcessCommandLine contains "Add-PSSnapin Microsoft.Exchange.Powershell.Snapin" - 1 - - 1
AccountName != "system"
ProcessCommandLine contains "HKLM"
- 1 - - 1
InitiatingProcessFileName in "chrome.exe,iexplore.exe,runtimebroker.exe"
ProcessCommandLine has "--gpu-launcher"
- 1 - - 1
InitiatingProcessCommandLine contains "-dhclient"
InitiatingProcessCommandLine contains "/etc/NetworkManager/dispatcher.d/"
- 1 - - 1
InitiatingProcessCommandLine has_any "/opt/vmware/certproxy/bing/certproxyService.sh" - 1 - - 1
FolderPath !startswith "/" - 1 - - 1
ProcessCommandLine has "key=clear"
ProcessCommandLine startswith "netsh"
- 1 - - 1
ProcessCommandLine has "say \\\" - 1 - - 1
InitiatingProcessFileName startswith "psexe" - 1 - - 1
ProcessCommandLine has "/mds"
ProcessCommandLine has "/mhp"
ProcessCommandLine has "/mnl"
ProcessCommandLine has "/mnt"
ProcessCommandLine has "bundlename=chromium"
ProcessCommandLine has "rsf"
- 1 - - 1
ProcessCommandLine contains "ecosetup"
ProcessCommandLine contains "highest"
ProcessCommandLine contains "spsextserv.exe"
- 1 - - 1
ProcessCommandLine contains "/run"
ProcessCommandLine contains "Windows Error Reporting"
- 1 - - 1
ProcessCommandLine contains "/fa"
ProcessCommandLine contains ":\\windows\\installer"
- 1 - - 1
ProcessCommandLine contains "del"
ProcessCommandLine contains "rmdir"
- 1 - - 1
ProcessCommandLine has "stop" - 1 - - 1
ProcessCommandLine contains "1"
ProcessCommandLine has "EnableBDEWithNoTPM"
ProcessCommandLine has "true"
- 1 - - 1
ProcessVersionInfoCompanyName has "Action1"
ProcessVersionInfoProductName has "Action1"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "AeroAdmin"
ProcessVersionInfoProductName has_any "AeroAdmin"
- 1 - - 1
ProcessVersionInfoCompanyName has "Ammyy"
ProcessVersionInfoProductName has "Ammyy Admin"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "anydesk software"
ProcessVersionInfoProductName has "anydesk"
- 1 - - 1
ProcessVersionInfoCompanyName has "AOMEI"
ProcessVersionInfoProductName has "AnyViewer"
- 1 - - 1
ProcessVersionInfoCompanyName has "Atera Networks" - 1 - - 1
ProcessVersionInfoCompanyName has "AweRay"
ProcessVersionInfoProductName has "AweSun"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "Barracuda MSP" - 1 - - 1
ProcessVersionInfoCompanyName has_any "BeyondTrust" - 1 - - 1
ProcessVersionInfoCompanyName has "Google"
ProcessVersionInfoProductName has "Chrome Remote Desktop"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "ConnectWise" - 1 - - 1
ProcessVersionInfoCompanyName has_any "DameWare"
ProcessVersionInfoFileDescription has "DameWare"
ProcessVersionInfoProductName has "DameWare"
- 1 - - 1
ProcessVersionInfoCompanyName has "NCH Software"
ProcessVersionInfoProductName has "DesktopNow"
- 1 - - 1
ProcessVersionInfoCompanyName has "Distant Software"
ProcessVersionInfoProductName has "Distant Desktop"
- 1 - - 1
ProcessVersionInfoCompanyName has "FleetDeck"
ProcessVersionInfoProductName has "FleetDeck"
- 1 - - 1
ProcessVersionInfoCompanyName has "getscreen.me"
ProcessVersionInfoProductName has "getscreen.me"
- 1 - - 1
ProcessVersionInfoCompanyName has "Enter Srl"
ProcessVersionInfoProductName has "Iperius Remote"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "Xlab"
ProcessVersionInfoProductName has_any "ISL Light"
- 1 - - 1
ProcessVersionInfoProductName has_any "LiteManager" - 1 - - 1
ProcessVersionInfoCompanyName has "LogMeIn"
ProcessVersionInfoProductName has_any "LogMeIn"
- 1 - - 1
ProcessVersionInfoProductName has "meshcentral" - 1 - - 1
ProcessVersionInfoProductName has "mRemoteNG" - 1 - - 1
ProcessVersionInfoCompanyName has_any "CloudBerry"
ProcessVersionInfoProductName has_any "RMM"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "N-Able" - 1 - - 1
ProcessVersionInfoCompanyName has_any "naverisk" - 1 - - 1
ProcessVersionInfoCompanyName has "netsupport" - 1 - - 1
ProcessVersionInfoCompanyName has_any "NinjaRMM"
ProcessVersionInfoProductName has "NinjaRMM"
- 1 - - 1
ProcessVersionInfoCompanyName has "Bravura Software LLC"
ProcessVersionInfoProductName has "OptiTune"
- 1 - - 1
ProcessVersionInfoCompanyName has "panorama9"
ProcessVersionInfoProductName has "panorama9"
- 1 - - 1
ProcessVersionInfoCompanyName has "Parsec"
ProcessVersionInfoProductName has "Parsec"
- 1 - - 1
ProcessVersionInfoCompanyName has "pcvisit software ag"
ProcessVersionInfoProductName has "pcvisit"
- 1 - - 1
ProcessVersionInfoProductName has "PDQConnectAgent" - 1 - - 1
ProcessVersionInfoCompanyName has "MMSoft Design"
ProcessVersionInfoProductName has "Pulseway"
- 1 - - 1
ProcessVersionInfoCompanyName has "realvnc" - 1 - - 1
ProcessVersionInfoCompanyName has "www.donkz.nl"
ProcessVersionInfoOriginalFileName has "rdp.exe"
ProcessVersionInfoProductName has "Remote Desktop Plus"
- 1 - - 1
ProcessVersionInfoCompanyName has "idrive"
ProcessVersionInfoProductName has_any "remotepc"
- 1 - - 1
ProcessVersionInfoCompanyName has "Remote Utilities"
ProcessVersionInfoProductName has "Remote Utilities"
- 1 - - 1
ProcessVersionInfoCompanyName has "RealVNC"
ProcessVersionInfoProductName has "rport"
- 1 - - 1
ProcessVersionInfoProductName has "rustdesk" - 1 - - 1
ProcessVersionInfoCompanyName has "Projector Inc"
ProcessVersionInfoProductName has "ScreenMeet"
- 1 - - 1
ProcessVersionInfoCompanyName has "Krämer IT Solutions GmbH"
ProcessVersionInfoProductName has_any "ServerEye"
- 1 - - 1
ProcessVersionInfoCompanyName has "ShowMyPC"
ProcessVersionInfoProductName has "ShowMyPC"
- 1 - - 1
ProcessVersionInfoCompanyName has "SimpleHelp"
ProcessVersionInfoProductName has "SimpleHelp"
- 1 - - 1
ProcessVersionInfoCompanyName has "Splashtop"
ProcessVersionInfoProductName has "Splashtop"
- 1 - - 1
ProcessVersionInfoCompanyName has "NanoSystems"
ProcessVersionInfoProductName has "SupRemo"
- 1 - - 1
ProcessVersionInfoCompanyName has "Servably, Inc."
ProcessVersionInfoProductName has "Syncro"
- 1 - - 1
ProcessVersionInfoCompanyName has_any "AmidaWare"
ProcessVersionInfoProductName has "Tactical RMM"
- 1 - - 1
ProcessVersionInfoCompanyName has "TeamViewer"
ProcessVersionInfoProductName has "TeamViewer"
- 1 - - 1
ProcessVersionInfoCompanyName has "TigerVNC"
ProcessVersionInfoProductName has "TigerVNC"
- 1 - - 1
ProcessVersionInfoCompanyName has "GlavSoft"
ProcessVersionInfoProductName has "TightVNC"
- 1 - - 1
ProcessVersionInfoCompanyName has "DucFabulous"
ProcessVersionInfoProductName has "UltraViewer"
- 1 - - 1
ProcessVersionInfoCompanyName has "XMReality"
ProcessVersionInfoProductName has "XMReality"
- 1 - - 1
ProcessVersionInfoCompanyName has "Zoho"
ProcessVersionInfoProductName has "Zoho Assist"
- 1 - - 1
InitiatingProcessFileName == "excel.exe" - 1 - - 1
ProcessCommandLine has_any "temp" - 1 - - 1
ProcessVersionInfoProductName has "rclone" - 1 - - 1
InitiatingProcessFileName == "WINWORD.EXE" - 1 - - 1
ProcessCommandLine has "HealthMailbox55x2yq"
ProcessCommandLine has_any "New-Mailbox"
- 1 - - 1
ProcessCommandLine has_all "-command" - 1 - - 1
InitiatingProcessCommandLine has_all "Set-MpPreference" - 1 - - 1
ProcessCommandLine has "VMBlastSG" - 1 - - 1
InitiatingProcessFileName has "ws_TomcatService.exe" - 1 - - 1
ProcessCommandLine has "REG_DWORD /d \"
ProcessCommandLine has_all "reg"
- 1 - - 1
InitiatingProcessCommandLine has ".bat"
InitiatingProcessParentFileName endswith "PSEXESVC.exe"
- 1 - - 1
InitiatingProcessFileName in "excel.exe,regsvr32.exe"
InitiatingProcessParentFileName has "excel.exe"
- 1 - - 1
InitiatingProcessCommandLine has "roaming"
InitiatingProcessFileName in "java.exe,javaw.exe"
ProcessCommandLine has "path antivirusproduct get displayname"
- 1 - - 1
InitiatingProcessFileName in "java.exe,javaw.exe" - 1 - - 1
InitiatingProcessCommandLine has "/bin/bash /tmp/"
ProcessCommandLine has "service apparmor stop"
- 1 - - 1
InitiatingProcessCommandLine has "php-cgi.exe"
ProcessCommandLine has_all "curl -fsSL"
- 1 - - 1
InitiatingProcessFileName in "cmd.exe,powershell.exe"
InitiatingProcessParentFileName startswith "tomcat"
ProcessCommandLine has_any "cmd.exe"
- 1 - - 1
ProcessCommandLine has "Set-MpPreference" - 1 - - 1
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" - 1 - - 1
Total 0 256 0 0 256

AccountName

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= system - 1 - - 1

ActionType

Value Connectors Content Items ASIM Parsers Other Parsers Total
InboundConnectionAccepted - 2 - - 2
FileCreated - 2 - - 2
BrowserLaunchedToOpenUrl - 2 - - 2
!= ListeningConnectionCreated - 1 - - 1
LogonSuccess - 1 - - 1
FileModified - 1 - - 1
NamedPipeEvent - 1 - - 1
RegistryKeyCreated - 1 - - 1
Add member to role - 1 - - 1
Add user - 1 - - 1
InteractiveLogon - 1 - - 1
RemoteInteractiveLogon - 1 - - 1
Reset user password - 1 - - 1
ResourceAccess - 1 - - 1
Sign-in - 1 - - 1
Update user - 1 - - 1

FolderPath

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith C:\\Program Files (x86)\\Microsoft Visual Studio - 1 - - 1
!startswith / - 1 - - 1

InitiatingProcessCommandLine

Value Connectors Content Items ASIM Parsers Other Parsers Total
has -n 6 - 3 - - 3
has 127.0.0.1 - 3 - - 3
has calc.exe - 3 - - 3
endswith 127.0.0.1 - 3 - - 3
has -a - 3 - - 3
has -nao - 3 - - 3
has -t - 3 - - 3
has /all - 3 - - 3
has $true - 2 - - 2
has /IM - 2 - - 2
has Set-MpPreference - 2 - - 2
has config - 2 - - 2
has_all advfirewall - 2 - - 2
contains <script> - 2 - - 2
has confluence - 2 - - 2
dllhost.exe - 2 - - 2
endswith rundll32.exe - 2 - - 2
contains //confluence - 2 - - 2
has .bat - 2 - - 2
has_any E9495B87-D950-4AB5-87A5-FF6D70BF3E90 - 1 - - 1
has Start - 1 - - 1
has /dev/shm/kdmtmpflush - 1 - - 1
has /d 1 - 1 - - 1
contains WinHttpAutoProxySvc - 1 - - 1
has start /MIN - 1 - - 1
contains -dhclient - 1 - - 1
contains /etc/NetworkManager/dispatcher.d/ - 1 - - 1
has_any /opt/vmware/certproxy/bing/certproxyService.sh - 1 - - 1
has_all Set-MpPreference - 1 - - 1
has roaming - 1 - - 1
has /bin/bash /tmp/ - 1 - - 1
has php-cgi.exe - 1 - - 1

InitiatingProcessFileName

Value Connectors Content Items ASIM Parsers Other Parsers Total
cmd.exe - 8 - - 8
excel.exe - 7 - - 7
winword.exe - 6 - - 6
explorer.exe - 6 - - 6
rundll32.exe - 6 - - 6
beasvc.exe - 5 - - 5
httpd.exe - 5 - - 5
w3wp.exe - 5 - - 5
outlook.exe - 5 - - 5
java.exe - 5 - - 5
startswith psexe - 4 - - 4
dllhost.exe - 3 - - 3
startswith tomcat - 3 - - 3
net.exe - 3 - - 3
mobsync.exe - 3 - - 3
wmiprvse.exe - 3 - - 3
powershell.exe - 3 - - 3
solarwinds.businesslayerhost.exe - 2 - - 2
netsh.exe - 2 - - 2
msiexec.exe - 2 - - 2
mshta.exe - 2 - - 2
SolarWinds.BusinessLayerHost.exe - 2 - - 2
winlogon.exe - 2 - - 2
javaw.exe - 2 - - 2
oracle.exe - 1 - - 1
WDExpress.exe - 1 - - 1
devenv.exe - 1 - - 1
wsreset.exe - 1 - - 1
changepk.exe - 1 - - 1
auditpol.exe - 1 - - 1
wscript.exe - 1 - - 1
svchost.exe - 1 - - 1
powerpnt.exe - 1 - - 1
launchpad.exe - 1 - - 1
sqlagent.exe - 1 - - 1
sqlps.exe - 1 - - 1
sqlservr.exe - 1 - - 1
UMWorkerProcess.exe - 1 - - 1
chrome.exe - 1 - - 1
iexplore.exe - 1 - - 1
runtimebroker.exe - 1 - - 1
WINWORD.EXE - 1 - - 1
has ws_TomcatService.exe - 1 - - 1
regsvr32.exe - 1 - - 1

InitiatingProcessFolderPath

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith C:\\Program Files (x86)\\Microsoft Visual Studio - 1 - - 1

InitiatingProcessParentFileName

Value Connectors Content Items ASIM Parsers Other Parsers Total
beasvc.exe - 5 - - 5
startswith tomcat - 4 - - 4
httpd.exe - 3 - - 3
w3wp.exe - 3 - - 3
!= cscript.exe - 2 - - 2
has spoolsv.exe - 2 - - 2
startswith psexe - 2 - - 2
svchost.exe - 1 - - 1
slui.exe - 1 - - 1
outlook.exe - 1 - - 1
Microsoft Excel - 1 - - 1
Microsoft Word - 1 - - 1
endswith PSEXESVC.exe - 1 - - 1
has excel.exe - 1 - - 1

InitiatingProcessVersionInfoProductName

Value Connectors Content Items ASIM Parsers Other Parsers Total
!= Android Studio - 1 - - 1

ProcessCommandLine

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains -ma - 6 - - 6
has -accepteula - 6 - - 6
has lsass - 6 - - 6
has deletejournal - 6 - - 6
has usn - 6 - - 6
has certutil - 5 - - 5
!contains /add - 5 - - 5
has /w - 5 - - 5
contains %temp% - 4 - - 4
has http - 4 - - 4
has config - 4 - - 4
has delete - 4 - - 4
has disabled - 4 - - 4
has sc - 4 - - 4
has Change - 4 - - 4
has SystemRestore - 4 - - 4
has disable - 4 - - 4
has lsass.exe - 3 - - 3
has msexchange - 3 - - 3
has sql - 3 - - 3
has stop-service - 3 - - 3
has ipconfig - 3 - - 3
has ping - 3 - - 3
has systeminfo - 3 - - 3
has timeout - 3 - - 3
has wget - 3 - - 3
has whoami - 3 - - 3
has /Upload - 3 - - 3
has_any /Transfer - 3 - - 3
has .jse - 3 - - 3
!contains /domain - 3 - - 3
has CL - 3 - - 3
has WEVTUTIL - 3 - - 3
has DownloadFile - 3 - - 3
has Invoke-Shellcode - 3 - - 3
has Invoke-WebRequest - 3 - - 3
has Net.WebClient - 3 - - 3
has shadowcopy delete - 3 - - 3
contains -e - 3 - - 3
has hklm - 2 - - 2
has sam - 2 - - 2
has save - 2 - - 2
!contains \\ - 2 - - 2
contains /do - 2 - - 2
contains /domain - 2 - - 2
contains group - 2 - - 2
contains user - 2 - - 2
has return - 2 - - 2
contains privilege:: - 2 - - 2
contains token:: - 2 - - 2
has sekurlsa - 2 - - 2
has IEX - 2 - - 2
has Start-BitsTransfer - 2 - - 2
has mpcmdrun.exe - 2 - - 2
has cl - 2 - - 2
has wbadmin - 2 - - 2
has wevtutil - 2 - - 2
has wmic - 2 - - 2
has wmic computersystem get domain - 2 - - 2
has programdata - 2 - - 2
has_any whoami /all - 2 - - 2
!contains ApplicationNo - 2 - - 2
!contains Cosmos - 2 - - 2
!contains CustomerGroup - 2 - - 2
!contains Unrestricted - 2 - - 2
!startswith POWERSHELL.EXE -C \ - 2 - - 2
contains $ - 2 - - 2
contains -split - 2 - - 2
contains > - 2 - - 2
contains @echo - 2 - - 2
contains encodedcommand - 2 - - 2
contains wget - 2 - - 2
startswith -q -s - 2 - - 2
has WebCache - 2 - - 2
has_any V01 - 2 - - 2
has -base64 - 2 - - 2
has -nosalt - 2 - - 2
has -out - 2 - - 2
has shadowcopy - 2 - - 2
!= msiexec.exe /V - 1 - - 1
has_any /exe - 1 - - 1
has_any out - 1 - - 1
has powershell.exe - 1 - - 1
has_all -ExecutionPolicy - 1 - - 1
has_all -WindowStyle - 1 - - 1
contains VSIxs - 1 - - 1
contains vsce-sign.exe - 1 - - 1
cmd.exe /c taskkill /im cmd.exe - 1 - - 1
startswith powershell.exe mshta.exe http - 1 - - 1
endswith cmd.exe /c SYSTEMINFO & TASKLIST - 1 - - 1
ps.exe -accepteula - 1 - - 1
contains abCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCCc - 1 - - 1
endswith cyzfc.dat, PointFunctionCall - 1 - - 1
has -noni -ep bypass $ - 1 - - 1
has .vbs /shell - 1 - - 1
!has Windows\\CCM\\ - 1 - - 1
contains frombase64 - 1 - - 1
has Dvr /go - 1 - - 1
has DisableIOAVProtection - 1 - - 1
contains -noni -ep bypass $zk= - 1 - - 1
contains https://www.jmj.com/personal/nauerthn_state_gov - 1 - - 1
contains }} -p - 1 - - 1
startswith -q -s {{ - 1 - - 1
endswith ,dll_u - 1 - - 1
has -export dll_u - 1 - - 1
endswith localgroup administrators admin /add - 1 - - 1
has echo - 1 - - 1
contains theme0 - 1 - - 1
has -p - 1 - - 1
contains New-MailboxExportRequest - 1 - - 1
contains Remove-MailboxExportRequest - 1 - - 1
contains EIKKEIKK - 1 - - 1
contains python - 1 - - 1
has bash -i >& /dev/tcp/ - 1 - - 1
has 1 - 1 - - 1
has UseLogonCredential - 1 - - 1
has WDigest - 1 - - 1
has dword - 1 - - 1
contains .class - 1 - - 1
has attrib +h +s +r - 1 - - 1
has_any apphelp.dll - 1 - - 1
endswith powercat.ps1 - 1 - - 1
has http: - 1 - - 1
contains TVqQAAMAAAAEAAA - 1 - - 1
contains payload - 1 - - 1
contains targetip - 1 - - 1
contains targetport - 1 - - 1
contains verifybackdoor - 1 - - 1
contains .b64decode( - 1 - - 1
contains .decode( - 1 - - 1
contains .decode64( - 1 - - 1
contains base64 --decode - 1 - - 1
contains .jse - 1 - - 1
contains questd - 1 - - 1
has osascript -e do shell script \ - 1 - - 1
has /tmp/e_ - 1 - - 1
has base64 - 1 - - 1
contains :\\recycler - 1 - - 1
contains /grant Everyone:F - 1 - - 1
contains /w - 1 - - 1
has /all - 1 - - 1
has /change - 1 - - 1
has /d - 1 - - 1
has /disable - 1 - - 1
has /quiet - 1 - - 1
has delete shadows - 1 - - 1
has -v 2 - 1 - - 1
has -v 2.0 - 1 - - 1
has -version 2 - 1 - - 1
has -version 2.0 - 1 - - 1
has E:javascript - 1 - - 1
contains $client = New-Object System.Net.Sockets.TCPClient - 1 - - 1
contains ProgramData\\pst - 1 - - 1
contains Add-PSSnapin Microsoft.Exchange.Powershell.Snapin - 1 - - 1
contains HKLM - 1 - - 1
has --gpu-launcher - 1 - - 1
has key=clear - 1 - - 1
startswith netsh - 1 - - 1
has say \\\ - 1 - - 1
has /mds - 1 - - 1
has /mhp - 1 - - 1
has /mnl - 1 - - 1
has /mnt - 1 - - 1
has bundlename=chromium - 1 - - 1
has rsf - 1 - - 1
contains ecosetup - 1 - - 1
contains highest - 1 - - 1
contains spsextserv.exe - 1 - - 1
contains /run - 1 - - 1
contains Windows Error Reporting - 1 - - 1
contains /fa - 1 - - 1
contains :\\windows\\installer - 1 - - 1
contains del - 1 - - 1
contains rmdir - 1 - - 1
has stop - 1 - - 1
contains 1 - 1 - - 1
has EnableBDEWithNoTPM - 1 - - 1
has true - 1 - - 1
has_any temp - 1 - - 1
has HealthMailbox55x2yq - 1 - - 1
has_any New-Mailbox - 1 - - 1
has_all -command - 1 - - 1
has VMBlastSG - 1 - - 1
has REG_DWORD /d \ - 1 - - 1
has_all reg - 1 - - 1
has path antivirusproduct get displayname - 1 - - 1
has service apparmor stop - 1 - - 1
has_all curl -fsSL - 1 - - 1
has_any cmd.exe - 1 - - 1
has Set-MpPreference - 1 - - 1

ProcessIntegrityLevel

Value Connectors Content Items ASIM Parsers Other Parsers Total
High - 3 - - 3

ProcessVersionInfoCompanyName

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Action1 - 1 - - 1
has_any AeroAdmin - 1 - - 1
has Ammyy - 1 - - 1
has_any anydesk software - 1 - - 1
has AOMEI - 1 - - 1
has Atera Networks - 1 - - 1
has AweRay - 1 - - 1
has_any Barracuda MSP - 1 - - 1
has_any BeyondTrust - 1 - - 1
has Google - 1 - - 1
has_any ConnectWise - 1 - - 1
has_any DameWare - 1 - - 1
has NCH Software - 1 - - 1
has Distant Software - 1 - - 1
has FleetDeck - 1 - - 1
has getscreen.me - 1 - - 1
has Enter Srl - 1 - - 1
has_any Xlab - 1 - - 1
has LogMeIn - 1 - - 1
has_any CloudBerry - 1 - - 1
has_any N-Able - 1 - - 1
has_any naverisk - 1 - - 1
has netsupport - 1 - - 1
has_any NinjaRMM - 1 - - 1
has Bravura Software LLC - 1 - - 1
has panorama9 - 1 - - 1
has Parsec - 1 - - 1
has pcvisit software ag - 1 - - 1
has MMSoft Design - 1 - - 1
has realvnc - 1 - - 1
has www.donkz.nl - 1 - - 1
has idrive - 1 - - 1
has Remote Utilities - 1 - - 1
has RealVNC - 1 - - 1
has Projector Inc - 1 - - 1
has Krämer IT Solutions GmbH - 1 - - 1
has ShowMyPC - 1 - - 1
has SimpleHelp - 1 - - 1
has Splashtop - 1 - - 1
has NanoSystems - 1 - - 1
has Servably, Inc. - 1 - - 1
has_any AmidaWare - 1 - - 1
has TeamViewer - 1 - - 1
has TigerVNC - 1 - - 1
has GlavSoft - 1 - - 1
has DucFabulous - 1 - - 1
has XMReality - 1 - - 1
has Zoho - 1 - - 1

ProcessVersionInfoFileDescription

Value Connectors Content Items ASIM Parsers Other Parsers Total
has DameWare - 1 - - 1

ProcessVersionInfoOriginalFileName

Value Connectors Content Items ASIM Parsers Other Parsers Total
has rdp.exe - 1 - - 1

ProcessVersionInfoProductName

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Action1 - 1 - - 1
has_any AeroAdmin - 1 - - 1
has Ammyy Admin - 1 - - 1
has anydesk - 1 - - 1
has AnyViewer - 1 - - 1
has AweSun - 1 - - 1
has Chrome Remote Desktop - 1 - - 1
has DameWare - 1 - - 1
has DesktopNow - 1 - - 1
has Distant Desktop - 1 - - 1
has FleetDeck - 1 - - 1
has getscreen.me - 1 - - 1
has Iperius Remote - 1 - - 1
has_any ISL Light - 1 - - 1
has_any LiteManager - 1 - - 1
has_any LogMeIn - 1 - - 1
has meshcentral - 1 - - 1
has mRemoteNG - 1 - - 1
has_any RMM - 1 - - 1
has NinjaRMM - 1 - - 1
has OptiTune - 1 - - 1
has panorama9 - 1 - - 1
has Parsec - 1 - - 1
has pcvisit - 1 - - 1
has PDQConnectAgent - 1 - - 1
has Pulseway - 1 - - 1
has Remote Desktop Plus - 1 - - 1
has_any remotepc - 1 - - 1
has Remote Utilities - 1 - - 1
has rport - 1 - - 1
has rustdesk - 1 - - 1
has ScreenMeet - 1 - - 1
has_any ServerEye - 1 - - 1
has ShowMyPC - 1 - - 1
has SimpleHelp - 1 - - 1
has Splashtop - 1 - - 1
has SupRemo - 1 - - 1
has Syncro - 1 - - 1
has Tactical RMM - 1 - - 1
has TeamViewer - 1 - - 1
has TigerVNC - 1 - - 1
has TightVNC - 1 - - 1
has UltraViewer - 1 - - 1
has XMReality - 1 - - 1
has Zoho Assist - 1 - - 1
has rclone - 1 - - 1

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index