SIEM

Process Execution Use Cases

This use case is purposefully separated from commandline activity. These detections assume you have all process execution details other than commandline (process name, PID, full path, etc.)

Grouped by Detection Method

MITRE ATT&CK Framework:

Match Alarm

Aggregate Count

Blacklist Alert

Whitelist Alert

Levenshtein Score Alert

Rolling Whitelist Alert

Shannon Entropy Score Alert

Threshold Alert

Log Source Examples

Possible False Positives

Resources