Skip to content

Latest commit

 

History

History
40 lines (33 loc) · 1.44 KB

MATCH-S00570.md

File metadata and controls

40 lines (33 loc) · 1.44 KB

Rules: WMIPRVSE Spawning Process

Description

Observes for child processes spawned by WMIPRVSE

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities device_hostname, user_username
Signal Name WMIPRVSE Spawning Process
Summary Expression Wmiprvse observed spawning child process {{baseImage}} on {{device_hostname}}
Score/Severity Static: 3
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0002, _mitreAttackTechnique:T1047

Vendors and Products

Fields Used

Origin Field
Normalized Schema device_hostname
Direct from Record fields['EventData.SubjectLogonId']
Normalized Schema isNull
Normalized Schema parentBaseImage
Normalized Schema user_userId
Normalized Schema user_username