Techniques
Sample rules
Trusted Developer Application Usage
- source: elastic
- technicques:
- T1127
Description
Identifies possibly suspicious activity using trusted Windows developer activity.
Detection logic
event.category:process and event.type:(start or process_started) and process.name:(MSBuild.exe or msxsl.exe)