New Process Created Via Taskmgr.EXE (3d7679bd-0c00-440c-97b0-3f204273e6c7)
Detects the creation of a process via the Windows task manager. This might be an attempt to bypass UAC
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) | Attack Pattern | New Process Created Via Taskmgr.EXE (3d7679bd-0c00-440c-97b0-3f204273e6c7) | Sigma-Rules | 1 |