title: Execution Of Not Existing File id: 71158e3f-df67-472b-930e-7d287acaa3e1 status: experimental description: Checks whether the image specified in a process creation event is not a full, absolute path (caused by process ghosting or other unorthodox methods to start a process) author: Max Altgelt date: 2021/12/09 references: - https://pentestlaboratories.com/2021/12/08/process-ghosting/ tags: - attack.defense_evasion logsource: category: process_creation product: windows detection: image_absolute_path: Image|contains: '\' filter: Image: null condition: not image_absolute_path and not filter falsepositives: - unknown level: high