Execution via stordiag.exe (961e0abb-1b1e-4c84-a453-aafe56ad0d34)
Detects the use of stordiag.exe to execute schtasks.exe systeminfo.exe and fltmc.exe
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Execution via stordiag.exe (961e0abb-1b1e-4c84-a453-aafe56ad0d34) | Sigma-Rules | System Binary Proxy Execution - T1218 (457c7820-d331-465a-915e-42f85500ccc4) | Attack Pattern | 1 |