Ps.exe Renamed SysInternals Tool — Detection Rule

Detects renamed SysInternals tool execution with a binary named ps.exe as used by Dragonfly APT group and documented in TA17-293A report

Read the full analysis on IntelFusions