Potential WinAPI Calls Via CommandLine (ba3f5c1b-6272-4119-9dbd-0bc8d21c2702)
Detects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Native API - T1106 (391d824f-0ef1-47a0-b0ee-c59a75e27670) | Attack Pattern | Potential WinAPI Calls Via CommandLine (ba3f5c1b-6272-4119-9dbd-0bc8d21c2702) | Sigma-Rules | 1 |