Event ID 9006000 — Image load (any)
Description
Image load (any)
Fields #
| Name | Description |
|---|---|
DeviceId | — |
Timestamp | — |
ActionType | — |
FileName | — |
FolderPath | — |
SHA256 | — |
InitiatingProcessFileName | — |
Detection Patterns #
Defense Evasion: Regsvr32
1 rule
Kusto Query Language
Execution: User Execution
1 rule
Kusto Query Language
References #
- Microsoft Defender XDR — advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceimageloadevents-table