Trusted Developer Utilities Proxy Execution

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This detection looks at process executions - in some cases with specific command line attributes to filter a lot of common noise.

Attribute Value
Type Analytic Rule
Solution FalconFriday
ID 5c2bb446-926f-4160-a233-21e335c2c290
Severity Medium
Status Available
Kind Scheduled
Tactics DefenseEvasion
Techniques T1127
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents FolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
InitiatingProcessFileName in "WDExpress.exe,devenv.exe"
InitiatingProcessFolderPath startswith "C:\\Program Files (x86)\\Microsoft Visual Studio"
ProcessCommandLine has_any "/exe"
ProcessCommandLine has_any "out"
?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to FalconFriday