Suspicious Msbuild Execution By Uncommon Parent Process

Rule Info

Id
33be4333-2c6b-44f4-ae28-102cdbde0a31
Author
frack113
Name
Suspicious Msbuild Execution By Uncommon Parent Process
Tags
attack.defense_evasion DEMO
Date
2022-11-17 00:00:00
Modified
None
Description
Detects suspicious execution of 'Msbuild.exe' by a uncommon parent process
Type
Community Rule

Rule History

Author
Date
Commit
Title
frack113
2022-11-18
Add proc_creation_win_susp_msbuild (#3708)