Service Installed By Unusual Client - System (71c276aa-49cd-43d2-b920-2dcd3e6962d5)
Detects a service installed by a client which has PID 0 or whose parent has PID 0
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) | Attack Pattern | Service Installed By Unusual Client - System (71c276aa-49cd-43d2-b920-2dcd3e6962d5) | Sigma-Rules | 1 |