Files
blue-team-tools/rules/windows/process_creation
svch0stz 3ec531979a Update proc_creation_win_webshell_spawn.yml
Example pulled from manage engine below:

Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
ParentImage: C:\Program Files\ManageEngine\SupportCenterPlus\jre\bin\java.exe
ParentCommandline: "..\jre\bin\java" -Dcatalina.home=.. -Dserver.home=.. -Dserver.stats=1000  <snip>
2022-05-15 14:57:21 +10:00
..
2022-03-07 17:11:00 +01:00
2022-05-07 10:37:55 +02:00
2022-03-17 16:48:41 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00
2022-05-13 11:52:31 +01:00