mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
iceid_dfir_coverage
This commit is contained in:
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
|
||||
status: production
|
||||
type: Hunting
|
||||
data_source:
|
||||
- - Windows Security 5140
|
||||
- Windows Security 5140
|
||||
description: The following analytic identifies object access on Windows administrative SMB shares (Admin$, IPC$, C$).
|
||||
This represents suspicious behavior as its commonly used by tools like PsExec/PaExec and others
|
||||
to stage service binaries before creating and starting a Windows service on remote
|
||||
|
||||
Reference in New Issue
Block a user