
Rule Info
Name
Suspicious Sysmon as Execution Parent
Author
Florian Roth (Nextron Systems), Tim Shelton (fp werfault)
Description
Detects suspicious process executions in which Sysmon itself is the parent of a process, which could be a sign of exploitation (e.g. CVE-2022-41120)
Date
2022-11-10 00:00:00
Modified
2023-10-23 00:00:00
Id
6d1058a4-407e-4f3a-a144-1968c11dc5c3
Tags
attack.privilege_escalation attack.t1068 cve.2022.41120 detection.emerging_threats DEMO
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4503 from @nasbench - Multiple Updates & Fixes
2023-10-28
Nasreddine Bencherchali
Merge PR #4482 From @nasbench - Add New Automation Workflows
2023-10-18
Florian Roth
Merge PR #4443 from @Neo23x0 - Fix Null Edge Case & Add New String
2023-09-13