Potential WinAPI Calls Via CommandLine — Detection Rule

Detects the use of WinAPI Functions via the commandline. As seen used by threat actors via the tool winapiexec

Read the full analysis on IntelFusions