LoFP LoFP / administrators may use the tasklist command to display a list of currently running processes. by itself, it does not indicate malicious activity. after obtaining a foothold, it's possible adversaries may use discovery commands like tasklist to get information about running processes.

Techniques

Sample rules

Process Discovery via Tasklist

Description

Adversaries may attempt to get information about running processes on a system.

Detection logic

event.category:process and event.type:(start or process_started) and process.name:tasklist.exe