Service Installed By Unusual Client - Security (c4e92a97-a9ff-4392-9d2d-7a4c642768ca)
Detects a service installed by a client which has PID 0 or whose parent has PID 0
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) | Attack Pattern | Service Installed By Unusual Client - Security (c4e92a97-a9ff-4392-9d2d-7a4c642768ca) | Sigma-Rules | 1 |