Home/Detection rules

Deployable detection rules

1 vendor-native detections · ready to paste into your SIEM · cross-linked to ATT&CK
technique T1057 ×

Detections

1 shown of 1
Elastic KQL low T1057 ↗
Process Discovery via Tasklist
Adversaries may attempt to get information about running processes on a system.
Show query
event.category:process and event.type:(start or process_started) and process.name:tasklist.exe
Showing 1-1 of 1