Detects Microsoft Network Monitor's nmcap.exe launched to capture network traffic. A rare binary on endpoints; attackers use it for on-host packet capture / credential sniffing. Authored from public Microsoft documentation. The rule matched on logsource `process_creation`. Verify the event genuinely matches the described behavior, and not a known legitimate case. The rule matches on these fields โ examine the exact value in the event:
Investigation queries (read-only):
Known benign causes for this rule:
The rule's references โ CTI context to qualify the incident: