Example from RTO
To identify this lateral movement: event.category: process and event.type : start and process.parent.name: mmc.exe
. Also look out for processes whose parent is svchost.exe ... -k DcomLaunch ...
Example from RTO
To identify this lateral movement: event.category: process and event.type : start and process.parent.name: mmc.exe
. Also look out for processes whose parent is svchost.exe ... -k DcomLaunch ...