Sysinternals PsSuspend Suspicious Execution (4beb6ae0-f85b-41e2-8f18-8668abc8af78)
Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses
Detects suspicious execution of Sysinternals PsSuspend, where the utility is used to suspend critical processes such as AV or EDR to bypass defenses