Detect Oulook Exe Writing A Zip File
This search looks for execution of process
outlook.exe where the process is writing a
.zip file to the disk.
Detect Oulook Exe Writing A Zip File Help
You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon.
Open in Search