Files
splunk-security_content/lookups/csv/prohibited_apps_launching_cmd.yml

12 lines
324 B
YAML

name: prohibited_apps_launching_cmd
id: e6ac9b38-051b-4e40-afd1-16837ddfe7fc
version: 3
creation_date: '2019-10-16'
modification_date: '2026-05-13'
author: Splunk Threat Research Team
lookup_type: csv
description: A list of processes that should not be launching cmd.exe
match_type:
- WILDCARD(prohibited_applications)