-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathMDE- Parent process spawning CMD.exe
4 lines (4 loc) · 1.12 KB
/
MDE- Parent process spawning CMD.exe
1
2
3
4
DeviceProcessEvents
|where ActionType == "ProcessCreated" and FileName == "cmd.exe" or FileName == "powershell.exe" or FileName == "powershell_ise.exe"
| where InitiatingProcessFileName contains "winword.exe" or InitiatingProcessFileName contains "EXCEL.exe" or InitiatingProcessFileName contains "winword.exe" or InitiatingProcessFileName contains "EXCEL.exe"or InitiatingProcessFileName contains "OUTLOOK.exe" or InitiatingProcessFileName contains "POWERPNT.exe" or InitiatingProcessFileName contains "visio.exe" or InitiatingProcessFileName contains "mspub.exe" or InitiatingProcessFileName contains "Acrobat.exe" or InitiatingProcessFileName contains "Acrord32.exe" or InitiatingProcessFileName contains "chrome.exe" or InitiatingProcessFileName contains "iexplore.exe" or InitiatingProcessFileName contains "opera.exe" or InitiatingProcessFileName contains "firefox.exe" or InitiatingProcessFileName contains "java.exe" or InitiatingProcessFileName contains "powershell.exe" or InitiatingProcessFileName contains "mshta.exe"or InitiatingProcessFileName contains "zoom.exe"
| project Timestamp, DeviceName, InitiatingProcessFileName, FileName