Home/Detection rules

Deployable detection rules

1 vendor-native detections · ready to paste into your SIEM · cross-linked to ATT&CK
technique T1033 ×

Detections

1 shown of 1
Elastic KQL low T1033 ↗
User Discovery via Whoami
The whoami application was executed on a Linux host. This is often used by tools and persistence mechanisms to test for privileged access.
Show query
event.category:process and event.type:(start or process_started) and process.name:whoami
Showing 1-1 of 1