Event Details High
Event Summary
Event ID
11
Risk Score
Status
ActiveTimestamp
Security Source
CrowdStrike Falcon (EDR)
Risk Category
Suspicious Process
User Information
Department
Engineering
Job Title
Production Developer II
Mitigations
Malware Remediation
Removed malicious files and registry entries
Applied
Applied by: security-admin
Event Details
| Tactic | persistence |
|---|---|
| Device Id | FINANCE-JS456 |
| Technique | T1136.001 |
| Command Line | cmd.exe /c net user /add backdoor P@ssw0rd123! |
| Detection Id | CS45678901 |
| Process Name | cmd.exe |
| Parent Process | winword.exe |
Raw JSON Data
{
"command_line": "cmd.exe /c net user /add backdoor P@ssw0rd123!",
"detection_id": "CS45678901",
"device_id": "FINANCE-JS456",
"parent_process": "winword.exe",
"process_name": "cmd.exe",
"tactic": "persistence",
"technique": "T1136.001"
}