New Network Trace Capture Started Via Netsh.EXE (d3c3861d-c504-4c77-ba55-224ba82d0118)
Detects the execution of netsh with the "trace" flag in order to start a network capture
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
New Network Trace Capture Started Via Netsh.EXE (d3c3861d-c504-4c77-ba55-224ba82d0118) | Sigma-Rules | Network Sniffing - T1040 (3257eb21-f9a7-4430-8de1-d8b6e288f529) | Attack Pattern | 1 |