Detect Renamed Winrar

Detect Renamed Winrar

Description

The following analtyic identifies renamed instances of WinRAR.exe. In most cases, it is not common for WinRAR to be used renamed, however it is common to be installed by a third party application and executed from a non-standard path. During triage, validate additional metadata from the binary that this is WinRAR. Review parallel processes and file modifications.

   Help

Detect Renamed Winrar Help

To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the Endpoint datamodel in the Processes node. In addition, confirm the latest CIM App 4.20 or higher is installed and the latest TA for the endpoint product.

   Search

Open in Search