Hi, Does anyone have a sample rule example for detecting WMIC Suspicious Scheduled Tasks and WMIC File Download? I am looking for both Scheduled Task and File Download. My search of Github did not fectch me any results unfortunately.
WMIC Suspicious Scheduled Tasks and WMIC File Download
Login to the community
Login with SSO
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
