Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies abnormal child processes of the Microsoft IIS Worker Process (w3wp.exe), which runs Web applications and handles requests for an application pool. Children such as cmd.exe or powershell.exe can indicate an exploit attempt.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 667c9f6c-8e41-4309-80a8-55fc3c5769bf |
| Tactics | InitialAccess, LateralMovement |
| Techniques | T1190, T1210 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
NewProcessName has_any "cmd.exe"ParentProcessName endswith "w3wp.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊