OTRF/detection-hackathon-apt29

13.D) Process Discovery

Cyb3rWard0g opened this issue · 0 comments

Description

The attacker performs local enumeration using various Windows API calls, specifically gathering running processes (T1057).