Renamed Plink Execution (1c12727d-02bf-45ff-a9f3-d49806a3cf43)
Detects the execution of a renamed version of the Plink binary
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) | Attack Pattern | Renamed Plink Execution (1c12727d-02bf-45ff-a9f3-d49806a3cf43) | Sigma-Rules | 1 |