-
Notifications
You must be signed in to change notification settings - Fork 0
/
MDE- Parent process spawning CMD.exe
4 lines (4 loc) · 1.12 KB
/
MDE- Parent process spawning CMD.exe
1
2
3
4
DeviceProcessEvents
|where ActionType == "ProcessCreated" and FileName == "cmd.exe" or FileName == "powershell.exe" or FileName == "powershell_ise.exe"
| where InitiatingProcessFileName contains "winword.exe" or InitiatingProcessFileName contains "EXCEL.exe" or InitiatingProcessFileName contains "winword.exe" or InitiatingProcessFileName contains "EXCEL.exe"or InitiatingProcessFileName contains "OUTLOOK.exe" or InitiatingProcessFileName contains "POWERPNT.exe" or InitiatingProcessFileName contains "visio.exe" or InitiatingProcessFileName contains "mspub.exe" or InitiatingProcessFileName contains "Acrobat.exe" or InitiatingProcessFileName contains "Acrord32.exe" or InitiatingProcessFileName contains "chrome.exe" or InitiatingProcessFileName contains "iexplore.exe" or InitiatingProcessFileName contains "opera.exe" or InitiatingProcessFileName contains "firefox.exe" or InitiatingProcessFileName contains "java.exe" or InitiatingProcessFileName contains "powershell.exe" or InitiatingProcessFileName contains "mshta.exe"or InitiatingProcessFileName contains "zoom.exe"
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName