OMIGOD SCX RunAsProvider ExecuteShellCommand - Auditd (045b5f9c-49f7-4419-a236-9854fb3c827a)
Rule to detect the use of the SCX RunAsProvider Invoke_ExecuteShellCommand to execute any UNIX/Linux command using the /bin/sh shell. SCXcore, started as the Microsoft Operations Manager UNIX/Linux Agent, is now used in a host of products including Microsoft Operations Manager. Microsoft Azure, and Microsoft Operations Management Suite.