PktMon.EXE Execution (f956c7c1-0f60-4bc5-b7d7-b39ab3c08908)
Detects execution of PktMon, a tool that captures network packets.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
PktMon.EXE Execution (f956c7c1-0f60-4bc5-b7d7-b39ab3c08908) | Sigma-Rules | Network Sniffing - T1040 (3257eb21-f9a7-4430-8de1-d8b6e288f529) | Attack Pattern | 1 |