Suspicious Splwow64 Without Params (1f1a8509-2cbb-44f5-8751-8e1571518ce2)
Detects suspicious Splwow64.exe process without any command line parameters
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Indirect Command Execution - T1202 (3b0e52ce-517a-4614-a523-1bd5deef6c5e) | Attack Pattern | Suspicious Splwow64 Without Params (1f1a8509-2cbb-44f5-8751-8e1571518ce2) | Sigma-Rules | 1 |