Detection rules › Sigma

Sysmon Blocked Executable

Severity
high
Author
Nasreddine Bencherchali (Nextron Systems)
Source
upstream

Triggers on any Sysmon "FileBlockExecutable" event, which indicates a violation of the configured block policy

Event coverage

ProviderEvent IDTitle
Sysmon27FileBlockExecutable

Stages and Predicates

Stage 1: selection