Deployable detection rules
1 vendor-native detections · ready to paste into your SIEM · cross-linked to ATT&CK
◈
Detections
1 shown of 1Process Discovery via Tasklist
Adversaries may attempt to get information about running processes on a system.
Show query
event.category:process and event.type:(start or process_started) and process.name:tasklist.exe
Showing 1-1 of 1