Potential Adplus.EXE Abuse — Detection Rule

Detects execution of "AdPlus.exe", a binary that is part of the Windows SDK that can be used as a LOLBIN in order to dump process memory and execute arbitrary commands.

Read the full analysis on IntelFusions