elastic
low
eql
Unusual Process Spawned by a Parent Process
A machine learning job has detected a suspicious Windows process. This process has been classified as malicious in two
ways. It was predicted to be malicious by the ProblemChild supervised ML model, and it was found to be an unusual child
process name, for the parent process, by an unsupervised ML model. Such a process may be an instance of suspicious or
malicious activity, possibly involving LOLbins, that may be resistant to detection using conventional search rules.