Elastic medium stable eql
Suspicious .NET Code Compilation
Identifies executions of .NET compilers with suspicious parent processes, which can indicate an attacker's attempt to compile code after delivery in order to bypass security mechanisms.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.name : ("csc.exe", "vbc.exe") and
process.parent.name : ("wscript.exe", "mshta.exe", "cscript.exe", "wmic.exe", "svchost.exe", "rundll32.exe", "cmstp.exe", "regsvr32.exe") Field Validations
Loading…
Comments (0)
Loading comments...