Hide Navigation Hide TOC Windows Processes Suspicious Parent Directory (96036718-71cc-4027-a538-d1587e0006a7) Detect suspicious parent processes of well-known Windows processes Cluster A Galaxy A Cluster B Galaxy B Level Rename System Utilities - T1036.003 (bd5b58a4-a52d-4a29-bc0d-3f1d3968eb6b) Attack Pattern Windows Processes Suspicious Parent Directory (96036718-71cc-4027-a538-d1587e0006a7) Sigma-Rules 1 Match Legitimate Name or Location - T1036.005 (1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2) Attack Pattern Windows Processes Suspicious Parent Directory (96036718-71cc-4027-a538-d1587e0006a7) Sigma-Rules 1 Rename System Utilities - T1036.003 (bd5b58a4-a52d-4a29-bc0d-3f1d3968eb6b) Attack Pattern Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern 2 Masquerading - T1036 (42e8de7b-37b2-4258-905a-6897815e58e0) Attack Pattern Match Legitimate Name or Location - T1036.005 (1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2) Attack Pattern 2