Phoenix
Sigma Intelligence
Beta
Home
Detections
Rules
Authors
MITRE
KB
Convert
Analytics
Coverage
Field Explorer
Testing
Ecosystem
Releases
About
Team
Philosophy
Search Rules
Rule Library
Sigma Rules
1 rule found for "Justin C."
3,707
Total
3,116
Detection
451
Emerging
137
Hunting
Filters
Detection
high
test
Suspicious Spool Service Child Process
Detects suspicious print spool service (spoolsv.exe) child processes.
Windows
Process Creation
TA0002 · Execution
T1203 · Exploitation for Client Execution
TA0004 · Privilege Escalation
T1068 · Exploitation for Privilege Escalation
Justin C.
+1
Sun Jul 11
windows