kqlElastic-2.0from elastic/detection-rules
High Number of Process and/or Service Terminations
Quality
92
FP risk
—
Forks
0
Views
0
Rule sourcerules/windows/impact_stop_process_service_threshold.toml
event.category:process and host.os.type:windows and event.type:start and process.name:(net.exe or sc.exe or taskkill.exe) and
process.args:(stop or pause or delete or "/PID" or "/IM" or "/T" or "/F" or "/t" or "/f" or "/im" or "/pid") and
not process.parent.name:(osquerybeat.exe or agentbeat.exe)