Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies Java spawning unusual child processes, which can indicate exploitation of the Java process. Java may not be the exploit target itself, but can be coaxed into executing malicious code via another service, such as Log4j or Spring-Core.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | 46c5b8dd-465c-4a51-b127-7561bbca02ff |
| Tactics | DefenseEvasion, InitialAccess |
| Techniques | T1190, T1202 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityEvent |
ParentProcessName endswith "java.exe"Process has_any "schtasks.exe" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊