title: Taskmgr as LOCAL_SYSTEM id: 9fff585c-c33e-4a86-b3cd-39312079a65f status: experimental description: Detects the creation of taskmgr.exe process in context of LOCAL_SYSTEM tags: - attack.defense_evasion - attack.t1036 author: Florian Roth date: 2018/03/18 modified: 2021/08/26 logsource: category: process_creation product: windows detection: selection: User|startswith: - 'NT AUTHORITY\SYSTEM' - 'AUTORITE NT\Sys' # French language settings Image|endswith: '\taskmgr.exe' condition: selection falsepositives: - Unknown level: high