Search and filter across all detection sources
20 rules
Whoami.EXE Execution Anomaly
Detects the execution of whoami.exe with suspicious parent processes.
Enumerate All Information With Whoami.EXE
Detects the execution of "whoami.exe" with the "/all" flag
Network Reconnaissance Activity
Detects a set of suspicious network related commands often used in recon stages
HackTool - SharpLdapWhoami Execution
Detects SharpLdapWhoami, a whoami alternative that queries the LDAP service on a domain controller
Renamed Whoami Execution
Detects the execution of whoami that has been renamed to a different name to avoid detection
WhoAmI as Parameter
Detects a suspicious process command line that uses whoami as first parameter (as e.g. used by EfsPotato)
Whoami.EXE Execution With Output Option
Detects the execution of "whoami.exe" with the "/FO" flag to choose CSV as output format or with redirection options to export the results to a file for later use.