Sysmon Usecases (IBM)
Introduction
Use Case 01 - Malicious File Injection and Execution
Scenario:
Red Flags:
Rules:
Unsigned Executable or DLL Loaded from Temp Directory
Process Launched from Temp Directory
Powershell Malicious Usage Detected
Process Created a Thread into System Process
Last updated