Potentially Suspicious GoogleUpdate Child Process

Rule Info

Tags
attack.defense_evasion DEMO
Name
Potentially Suspicious GoogleUpdate Child Process
Id
84b1ecf9-6eff-4004-bafb-bae5c0e251b2
Date
2023-05-15 00:00:00
Modified
2023-05-22 00:00:00
Description
Detects potentially suspicious child processes of "GoogleUpdate.exe"
Author
Nasreddine Bencherchali (Nextron Systems)
Type
Community Rule

Rule History

Title
Author
Commit
Date
Update proc_creation_win_googleupdate_susp_child_process.yml
frack113
2023-05-30
fix: FP in prod env
phantinuss
2023-05-22
feat: new rules, updates and goofy guineapig stuff (#4229)
Nasreddine Bencherchali
2023-05-15