Suspicious protected process execution

Identifies unprivileged process spawning a child with protected integrity level. This indicates an unusual behavior that is often associated with attempts to tamper with or freeze endpoint protection components.

Back to all rules