PUA - Wsudo Suspicious Execution — Detection Rule

Detects usage of wsudo (Windows Sudo Utility). Which is a tool that let the user execute programs with different permissions (System, Trusted Installer, Administrator...etc)

Read the full analysis on IntelFusions