Detect Suspicious Windows Command-Line Activity Using System Utilities
The query analyzes Windows ProcessRollup2 events to identify unusual use of common administrative tools (e.g., net.exe, sc.exe, nltest.exe, systeminfo.exe). It assigns behavior weights based on command-line patterns, aggregates activity per host and hour, flags systems with high or frequent activity, and provides direct links for host investigation in Falcon.
CQL · Falcon Next-Gen SIEMCopy query
Loading query…Detect_Suspicious_Windows_Command-Line_Activity_Using_System_Utilities.yml
CrowdStrike
Hunting
Endpoint
Insight
