Skip to content

Latest commit

 

History

History
37 lines (30 loc) · 1.2 KB

MATCH-S00508.md

File metadata and controls

37 lines (30 loc) · 1.2 KB

Rules: Zoom Child Process

Description

Observes for Zoom creating child processes

Additional Details

Detail Value
Type Templated Match
Category Execution
Apply Risk to Entities device_hostname, user_username
Signal Name Zoom Child Process
Summary Expression Detected Zoom spawning child process: {{baseImage}} on host: {{device_hostname}}
Score/Severity Static: 1
Enabled by Default True
Prototype True
Tags _mitreAttackTactic:TA0002

Vendors and Products

Fields Used

Origin Field
Normalized Schema baseImage
Normalized Schema device_hostname
Normalized Schema lower
Normalized Schema parentBaseImage
Normalized Schema user_username