New Network Trace Capture Started Via Netsh.EXE — Detection Rule

Detects the execution of netsh with the "trace" flag in order to start a network capture

Read the full analysis on IntelFusions