==================================================

CREATED: WIN-SERVICE-RANDOM-NAME-NUMERIC (#1404)

Description

This detector identifies processes with a parent process of services.exe and a process_name that consists of only integers. This behavior is consistent with malware families that generate a large number of random service names across an environment.

ATT&CK Technique T1035

Did this answer your question?