New Deployed Rules

Process CreationMMC20 Lateral Movement Process CreationMMC Spawning Windows Shell Process CreationPotential Arbitrary Command Execution Using Msdt.EXE Process CreationSuspicious MSDT Parent Process Process CreationRemotely Hosted HTA File Executed Via Mshta.EXE Process CreationSuspicious JavaScript Execution Via Mshta.EXE Process CreationPotential LethalHTA Technique Execution Process CreationMSHTA Suspicious Execution 01 Process CreationPotential MsiExec Masquerading Process CreationPotential Process Injection Via Msra.EXE […]

Time to market

One-day SIEM integration