Potential Defense Evasion Via Binary Rename — Detection Rule

Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.

Read the full analysis on IntelFusions