SCX Execute RunAs Providers

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query uses AUOMS security events to examine SCX Execute RunAs providers. These providers execute UNIX/Linux commands/scripts from /var/opt/microsoft/scx/tmp. SCXcore is used in various Microsoft products.

Attribute Value
Type Hunting Query
Solution Syslog
ID 0d298a1d-1a08-4f4b-8b28-687bfe0012e8
Severity High
Tactics InitialAccess, Execution
Techniques T1190, T1203
Required Connectors Syslog, SyslogAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
Syslog SyslogMessage has "AUOMS_EXECVE" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Syslog