Hacktool Execution - PE Metadata — Detection Rule

Detects the execution of different Windows based hacktools via PE metadata (company, product, etc.) even if the files have been renamed

Read the full analysis on IntelFusions