Skip to content

Latest commit

 

History

History
33 lines (26 loc) · 948 Bytes

MATCH-S00439.md

File metadata and controls

33 lines (26 loc) · 948 Bytes

Rules: Psr.exe Capture Screenshots

Description

The psr.exe captures desktop screenshots and saves them on the local machine.

Additional Details

Detail Value
Type Templated Match
Category Collection
Apply Risk to Entities device_hostname, device_ip, user_username
Signal Name Psr.exe Capture Screenshots
Summary Expression Process: {{baseImage}} executed on host: {{device_hostname}}
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0009, _mitreAttackTechnique:T1113

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema commandLine
Normalized Schema device_hostname
Normalized Schema device_ip
Normalized Schema user_username