← Library
kqlElastic-2.0from elastic/detection-rules

High Number of Process and/or Service Terminations

Quality
92
FP risk
Forks
0
Views
0
ATT&CK techniques
Rule sourcerules/windows/impact_stop_process_service_threshold.toml
event.category:process and host.os.type:windows and event.type:start and process.name:(net.exe or sc.exe or taskkill.exe) and
 process.args:(stop or pause or delete or "/PID" or "/IM" or "/T" or "/F" or "/t" or "/f" or "/im" or "/pid") and
 not process.parent.name:(osquerybeat.exe or agentbeat.exe)