Skip to content

Commit

Permalink
Add proc_creation_win_parent_run_itself
Browse files Browse the repository at this point in the history
  • Loading branch information
frack113 committed Feb 4, 2025
1 parent 2bfb093 commit ca50124
Showing 1 changed file with 20 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
title: Executable Run Itself
id: bafd07c6-3ea5-454a-b4be-058fbb073de7
status: experimental
description: Detects an executable that executes himself
references:
- https://www.joesandbox.com/analysis/1605063/0/html
author: frack113
date: 2025-02-04
tags:
- attack.defense-evasion
logsource:
category: process_creation
product: windows
detection:
selection:
Image|fieldref: ParentImage
condition: selection
falsepositives:
- Unknown
level: medium

0 comments on commit ca50124

Please sign in to comment.