Microsoft Windows AMSI
This pack includes Cortex XSIAM content.
This pack requires an XDR Agent to be installed on the relevant endpoints.
The Windows Antimalware Scan Interface (AMSI) is a security feature in Windows OSs that allows services to scan for files, memory and other data for threats.
This pack includes Cortex XSIAM content.
This pack requires an XDR Agent to be installed on the relevant endpoints.
Name | Description |
---|---|
Microsoft Windows AMSI Security Modeling Rule |
Name | Description |
---|---|
Microsoft Windows AMSI Parsing Rule |
Updated the Modeling Rule schema with additional fields.
The Windows Antimalware Scan Interface (AMSI) is a security feature in Windows OSs that allows services to scan for files, memory and other data for threats.
Certification | Certified | Read more |
Supported By | Cortex | |
Created | August 10, 2023 | |
Last Release | August 31, 2023 |