iceid_dfir_coverage

This commit is contained in:
tccontre
2023-05-23 15:46:58 +02:00
parent 566287f6b8
commit d667a02230
@@ -6,7 +6,7 @@ author: Teoderick Contreras, Splunk
status: production
type: Hunting
data_source:
- - Windows Security 5140
- Windows Security 5140
description: The following analytic identifies object access on Windows administrative SMB shares (Admin$, IPC$, C$).
This represents suspicious behavior as its commonly used by tools like PsExec/PaExec and others
to stage service binaries before creating and starting a Windows service on remote