Stopping multiple processes using taskkill

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query checks for attempts to stop at least 10 separate processes using the taskkill.exe utility. Run query

Attribute Value
Type Hunting Query
Solution GitHub Only
ID f8e4bee5-bc59-45f9-86e5-3b0a1bd1b572
Tactics Ransomware
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceProcessEvents ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries