- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-14-2024 03:11 AM
Dear All,
Do you know why the content updated, cannot open the task manager?
"ruleId": "bioc.masqueraded_process_msft",
"fileIdx": 0,
"modules": [],
"profile": "Malware",
"sockets": [],
"trigger": 0,
"moduleId": "COMPONENT_DSE",
"policyId": "d54b10f0ce0949db97b0f8bf6bda74d9",
"ruleName": "masqueraded_process_msft",
"severity": 4,
"tacticId": [
"TA0005",
"TA0002"
],
"canUpload": 1,
"ipBlocked": 0,
"processes": [
{
"pid": 9748,
"userIdx": 0,
"parentId": 9032,
"exeFileIdx": 0,
"instanceId": "Adp19lm1jDkAACYUAAAAAA==",
"terminated": 1,
"causalityId": "Adp19lm1jDkAACYUAAAAAA==",
"commandLine": "\"C:\\Windows\\system32\\taskmgr.exe\" /4",
"terminationReportId": "f80c05c2d9f24dda94aa8beff3ea16b8"
}
],
"terminate": 1,
"containers": [],
"description": "Behavioral Threat",
"techniqueId": [
"T1036.005"
],
"postDetected": 0,
"telemetryEdr": {
"actors": "",
"events": "",
"osActors": "",
"causalityActors": "",
"injectingActors": ""
},
"eventCategory": "prevention",
"preventionKey": "8d1a646687984b6987b7822deda5da7b",
"scriptResults": {},
"sourceProcess": {
"md5": "94ae29b49447daae37e07fd2264bb34b",
"pid": 9748,
"user": {
"userName": "",
"domainUser": "",
"userDomain": ""
},
"sha256": "78a68d19ef89ef39b26a85d5948d3a5051568674e2a4842ba10e3ddcb68eee6e",
"signers": [
"Microsoft Corporation"
],
"userIdx": 0,
"version": "10.0.19041.4123 (WinBuild.160101.0800)",
"fileName": "Taskmgr.exe",
"fileSize": "1214904",
"parentId": 9032,
"exeFileIdx": 0,
"instanceId": "Adp19lm1jDkAACYUAAAAAA==",
"terminated": 1,
"causalityId": "Adp19lm1jDkAACYUAAAAAA==",
"commandLine": "\"C:\\Windows\\system32\\taskmgr.exe\" /4",
"companyName": "Microsoft Corporation",
"rawFullPath": "C:\\Windows\\System32\\Taskmgr.exe",
"versionCopyright": "© Microsoft Corporation. All rights reserved.",
"versionDescription": "Task Manager",
"terminationReportId": "f80c05c2d9f24dda94aa8beff3ea16b8",
"versionInternalName": "Task Manager",
"versionOriginalName": "Taskmgr.exe"