Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies the default installation process executing suspect applications, such as powershell, schtasks, cmd and other applications that can by abused by built in modules.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 749f7e2c-5eeb-407d-a5ef-cfcecbe5d810 |
| Tactics | CommandAndControl, Execution |
| Techniques | T1059.001, T1059.003, T1219 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
CommandLine has_any "-kvm1"NewProcessName has "meshagent.exe"NewProcessName has_any "cmd.exe"ParentProcessName has "meshagent.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊