Skip to content

[Rule Tuning] Remote Execution via File Shares #5057

@janniten

Description

@janniten

Link to Rule

No response

Rule Tuning Type

Behavioral Tuning - Refining rules to better detect deviations from typical behavior.

Description

In the rule's definition a reference to "Veeam.SQL.Service" in the file part of the sequence.
In our enviroment we use veeam and we are seeing that the file copied is Veeam.SQL.Service.exe

Example Data

Image

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions