Win Susp Computer Name Containing Samtheadmin (39698b3f-da92-4bc6-bfb5-645a98386e45)
Detects suspicious computer name samtheadmin-{1..100}$ generated by hacktool
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Win Susp Computer Name Containing Samtheadmin (39698b3f-da92-4bc6-bfb5-645a98386e45) | Sigma-Rules | Valid Accounts - T1078 (b17a1a56-e99c-403c-8948-561df0cffe81) | Attack Pattern | 1 |