Skip to content

New Query: Process Execution directly from SMB share or SMB-mapped path#62

Merged
dweissbacher merged 1 commit into
mainfrom
submission/83f198dd-51a3-4485-a2b4-4231c6aebad6
Jun 5, 2026
Merged

New Query: Process Execution directly from SMB share or SMB-mapped path#62
dweissbacher merged 1 commit into
mainfrom
submission/83f198dd-51a3-4485-a2b4-4231c6aebad6

Conversation

@byteray-cql-hub-bot

Copy link
Copy Markdown
Contributor

New Query Submission

Name: Process Execution directly from SMB share or SMB-mapped path
Author: Kundan Kumar
Submission ID: 83f198dd-51a3-4485-a2b4-4231c6aebad6

Description

This query detects remote process execution over SMB (Server Message Block) on CrowdStrike Falcon monitored endpoints — a strong indicator of lateral movement, remote code execution, or ransomware spreading across the network.


This PR was automatically created by the CQL Hub submission pipeline.

@dweissbacher dweissbacher merged commit 634fdfe into main Jun 5, 2026
2 checks passed
@dweissbacher dweissbacher deleted the submission/83f198dd-51a3-4485-a2b4-4231c6aebad6 branch June 5, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant