T1057 Process Discovery
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057)…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
- HackTool - PCHunter Executionhightest · windows
- Potential Process Reconnaissance via Wmic.EXEmediumtest · windows
- Recon Command Output Piped To Findstr.EXEmediumtest · windows
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.