Suspicious SysAidServer Child (60bfeac3-0d35-4302-8efb-1dd16f715bc6)
Detects suspicious child processes of SysAidServer (as seen in MERCURY threat actor intrusions)
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Suspicious SysAidServer Child (60bfeac3-0d35-4302-8efb-1dd16f715bc6) | Sigma-Rules | Exploitation of Remote Services - T1210 (9db0cf3a-a3c9-4012-8268-123b9db6fd82) | Attack Pattern | 1 |