Detect Oulook Exe Writing A Zip File
This search looks for execution of process
outlook.exe where the process is writing a
.zip file to the disk.
This content is not mapped to any local saved search. Add mapping
Detect Oulook Exe Writing A Zip File Help
You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response products, such as Carbon Black, or endpoint data sources, such as Sysmon.
Open in Search