Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE (37db85d1-b089-490a-a59a-c7b6f984f480)
Detects usage of "findstr" with the argument "385201". Which could indicate potential discovery of an installed Sysinternals Sysmon service using the default driver altitude (even if the name is changed).