T1546 – Event Triggered Execution (Sysmon Detection)
Sysmon Alert Details Alert ID: SYSMON-EVENT-TRIGGER-1546-7842 Alert Time: 2024-02-16 10:30:15 EST Severity: HIGH (85/100) Source: Sysmon (Event ID 1 – Process Creation) Rule: “WMI Event Subscription – Suspicious Command Line” MITRE ATT&CK: T1546.003 – Event Triggered Execution: WMI Event Subscription Alert Details: Event ID: 1 (Process Creation) – WMI Event Subscription Time: 10:25 EST Host: … Read more