Elastic low stable eql
System Information Discovery via Windows Command Shell
Identifies the execution of discovery commands to enumerate system information, files, and folders using the Windows Command Shell.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.name : "cmd.exe" and process.args : "/c" and process.args : ("set", "dir") and
not process.parent.executable : (
"?:\\Program Files\\*",
"?:\\Program Files (x86)\\*",
"?:\\PROGRA~1\\*",
"?:\\TeamCity\\jre\\bin\\java.exe"
) and
not process.args : (
"*\\db\\rabbit@*", "*/db/rabbit@*",
"*rabbitmq/db/*", "*RabbitMQ\\db*"
) and
not process.parent.args : "*C:\\Program Files (x86)\\Tanium\\Tanium Client\\TPython\\TPython.bat*" Field Validations
Loading…
Comments (0)
Loading comments...