Detect Outlook Exe Writing A Zip File

Detect Outlook Exe Writing A Zip File

Description

This search looks for execution of process outlook.exe where the process is writing a .zip file to the disk.

   Help

Detect Outlook Exe Writing A Zip File Help

You must be ingesting data that records filesystem and process activity from your hosts to populate the Endpoint data model. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or endpoint data sources, such as Sysmon.

   Search

Open in Search