Suspicious object symbolic link creation

Identifies the creation of the object symbolic link inside the object manager namespace by untrusted or unusual processes. Adversaries may exploit object symbolic links to trick system processes into executing malicious payloads.

Back to all rules