VMToolsd Suspicious Child Process (5687f942-867b-4578-ade7-1e341c46e99a)
Detects suspicious child process creations of VMware Tools process which may indicate persistence setup
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
VMToolsd Suspicious Child Process (5687f942-867b-4578-ade7-1e341c46e99a) | Sigma-Rules | Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) | Attack Pattern | 1 |