Potential Defense Evasion Via Rename Of Highly Relevant Binaries — Detection Rule

Detects the execution of a renamed binary often used by attackers or malware leveraging new Sysmon OriginalFileName datapoint.

Read the full analysis on IntelFusions