Suspicious Child Process Of Manage Engine ServiceDesk

Rule Info

Name
Suspicious Child Process Of Manage Engine ServiceDesk
Author
Florian Roth (Nextron Systems)
Description
Detects suspicious child processes of the "Manage Engine ServiceDesk Plus" Java web service
Date
2023-01-18 00:00:00
Modified
2023-08-29 00:00:00
Id
cea2b7ea-792b-405f-95a1-b903ea06458f
Tags
attack.command_and_control attack.t1102 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4406 from @nasbench - Multiple Updates & Additions
2023-09-07
Tessa Georgen
Merge PR #4392 from @tjgeorgen - Update MITRE Tags
2023-08-28
Nasreddine Bencherchali
chore: add nextron authors tag
2023-02-01
Nasreddine Bencherchali
fix: filter and add missing modified
2023-01-21
Nasreddine Bencherchali
fix: apply suggestions from code review
2023-01-21
Florian Roth
refactor: extended some exploitation rules - sub procs
2023-01-21
Nasreddine Bencherchali
fix: change link to permalink
2023-01-19
Florian Roth
docs: changed wording
2023-01-19
Florian Roth
rule: Manage Engine suspicious sub process
2023-01-19