Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 1
id: 4a30ac0c-b9d6-4e01-b71a-5f851bbf4259
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐
'
- '๐'
- '๐คฃ'
- '๐ฅฒ'
- '๐ฅน'
- 'โบ๏ธ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐ฅฐ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐คช'
- '๐คจ'
- '๐ง'
- '๐ค'
- '๐'
- '๐ฅธ'
- '๐คฉ'
- '๐ฅณ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- 'โน๏ธ'
- '๐ฃ'
- '๐'
- '๐ซ'
- '๐ฉ'
- '๐ฅบ'
- '๐ข'
- '๐ญ'
- '๐ฎโ๐จ'
- '๐ค'
- '๐ '
- '๐ก'
- '๐คฌ'
- '๐คฏ'
- '๐ณ'
- '๐ฅต'
- '๐ฅถ'
- '๐ฑ'
- '๐จ'
- '๐ฐ'
- '๐ฅ'
- '๐'
- '๐ซฃ'
- '๐ค'
- '๐ซก'
- '๐ค'
- '๐ซข'
- '๐คญ'
- '๐คซ'
- '๐คฅ'
- '๐ถ'
- '๐ถโ๐ซ๏ธ'
- '๐'
- '๐'
- '๐ฌ'
- '๐ซ '
- '๐'
- '๐ฏ'
- '๐ฆ'
- '๐ง'
- '๐ฎ'
- '๐ฒ'
- '๐ฅฑ'
- '๐ด'
- '๐คค'
- '๐ช'
- '๐ต'
- '๐ตโ๐ซ'
- '๐ซฅ'
- '๐ค'
- '๐ฅด'
- '๐คข'
- '๐คฎ'
- '๐คง'
- '๐ท'
- '๐ค'
- '๐ค'
- '๐ค'
- '๐ค '
- '๐'
- '๐ฟ'
- '๐น'
- '๐บ'
- '๐คก'
- '๐ฉ'
- '๐ป'
- '๐'
- 'โ ๏ธ'
- '๐ฝ'
- '๐พ'
- '๐ค'
- '๐'
- '๐บ'
- '๐ธ'
- '๐น'
- '๐ป'
- '๐ผ'
- '๐ฝ'
- '๐'
- '๐ฟ'
- '๐พ'
- '๐'
- '๐ค'
- '๐'
- 'โ'
- '๐'
- '๐'
- '๐ค'
- '๐ค'
- 'โ๏ธ'
- '๐ค'
- '๐ซฐ'
- '๐ค'
- '๐ค'
- '๐ค'
- '๐ซต'
- '๐ซฑ'
- '๐ซฒ'
- '๐ซณ'
- '๐ซด'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- 'โ๏ธ'
- '๐'
- '๐'
- 'โ'
- '๐'
- '๐ค'
- '๐ค'
- '๐'
- '๐ซถ'
- '๐'
- '๐'
- '๐คฒ'
- '๐ค'
- '๐'
- 'โ๏ธ'
- '๐ช'
- '๐ฆพ'
- '๐ฆต'
- '๐ฆฟ'
- '๐ฆถ'
- '๐ฃ'
- '๐'
- '๐ฆป'
- '๐'
- '๐ซ'
- '๐ซ'
- '๐ง '
- '๐ฆท'
- '๐ฆด'
- '๐'
- '๐'
- '๐
'
- '๐'
- '๐ซฆ'
- '๐'
- '๐ฉธ'
- '๐ถ'
- '๐ง'
- '๐ง'
- '๐ฆ'
- '๐ฉ'
- '๐ง'
- '๐จ'
- '๐ฉโ๐ฆฑ'
- '๐งโ๐ฆฑ'
- '๐จโ๐ฆฑ'
- '๐ฉโ๐ฆฐ'
- '๐งโ๐ฆฐ'
- '๐จโ๐ฆฐ'
- '๐ฑโโ๏ธ'
- '๐ฑ'
- '๐ฑโโ๏ธ'
- '๐ฉโ๐ฆณ'
- '๐งโ๐ฆณ'
- '๐จโ๐ฆณ'
- '๐ฉโ๐ฆฒ'
- '๐งโ๐ฆฒ'
- '๐จโ๐ฆฒ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐ต'
- '๐ง'
- '๐ด'
- '๐ฒ'
- '๐ณโโ๏ธ'
- '๐ณ'
- '๐ณโโ๏ธ'
- '๐ง'
- '๐ฎโโ๏ธ'
- '๐ฎ'
- '๐ฎโโ๏ธ'
- '๐ทโโ๏ธ'
- '๐ท'
- '๐ทโโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐ต๏ธโโ๏ธ'
- '๐ต๏ธ'
- '๐ต๏ธโโ๏ธ'
- '๐ฉโโ๏ธ'
- '๐งโโ๏ธ'
- '๐จโโ๏ธ'
- '๐ฉโ๐พ'
- '๐งโ๐พ'
- '๐จโ๐พ'
- '๐ฉโ๐ณ'
- '๐งโ๐ณ'
- '๐จโ๐ณ'
- '๐ฉโ๐'
- '๐งโ๐'
- '๐จโ๐'
- '๐ฉโ๐ค'
- '๐งโ๐ค'
- '๐จโ๐ค'
- '๐ฉโ๐ซ'
- '๐งโ๐ซ'
- '๐จโ๐ซ'
- '๐ฉโ๐ญ'
- '๐งโ๐ญ'
- '๐จโ๐ญ'
- '๐ฉโ๐ป'
- '๐งโ๐ป'
- '๐จโ๐ป'
- '๐ฉโ๐ผ'
- '๐งโ๐ผ'
- '๐จโ๐ผ'
- '๐ฉโ๐ง'
- '๐งโ๐ง'
- '๐จโ๐ง'
- '๐ฉโ๐ฌ'
- '๐งโ๐ฌ'
- '๐จโ๐ฌ'
- '๐ฉโ๐จ'
- '๐งโ๐จ'
- '๐จโ๐จ'
- '๐ฉโ๐'
- '๐งโ๐'
- '๐จโ๐'
- '๐ฉโโ๏ธ'
- '๐งโโ๏ธ'
- '๐จโโ๏ธ'
- '๐ฉโ๐'
- '๐งโ๐'
- '๐จโ๐'
- '๐ฉโโ๏ธ'
- '๐งโโ๏ธ'
- '๐จโโ๏ธ'
- '๐ฐโโ๏ธ'
- '๐ฐ'
- '๐ฐโโ๏ธ'
- '๐คตโโ๏ธ'
- '๐คต'
- '๐คตโโ๏ธ'
- '๐ธ'
- '๐ซ
'
- '๐คด'
- '๐ฅท'
- '๐ฆธโโ๏ธ'
- '๐ฆธ'
- '๐ฆธโโ๏ธ'
- '๐ฆนโโ๏ธ'
- '๐ฆน'
- '๐ฆนโโ๏ธ'
- '๐คถ'
- '๐งโ๐'
- '๐
'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐ง'
- '๐ผ'
- '๐คฐ'
- '๐ซ'
- '๐ซ'
- '๐คฑ'
- '๐ฉโ๐ผ'
- '๐งโ๐ผ'
- '๐จโ๐ผ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐
โโ๏ธ'
- '๐
'
- '๐
โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐คฆโโ๏ธ'
- '๐คฆ'
- '๐คฆโโ๏ธ'
- '๐คทโโ๏ธ'
- '๐คท'
- '๐คทโโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐
'
- '๐'
- '๐บ'
- '๐ฏโโ๏ธ'
- '๐ฏ'
- '๐ฏโโ๏ธ'
- '๐ด'
- '๐ฉโ๐ฆฝ'
- '๐งโ๐ฆฝ'
- '๐จโ๐ฆฝ'
- '๐ฉโ๐ฆผ'
- '๐งโ๐ฆผ'
- '๐จโ๐ฆผ'
- '๐ถโโ๏ธ'
- '๐ถ'
- '๐ถโโ๏ธ'
- '๐ฉโ๐ฆฏ'
- '๐งโ๐ฆฏ'
- '๐จโ๐ฆฏ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐โโ๏ธ'
- '๐'
- '๐โโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง'
- '๐งโโ๏ธ'
- '๐ญ'
- '๐งโ๐คโ๐ง'
- '๐ฌ'
- '๐ซ'
- '๐ฉโโค๏ธโ๐ฉ'
- '๐'
- '๐จโโค๏ธโ๐จ'
- '๐ฉโโค๏ธโ๐จ'
- '๐ฉโโค๏ธโ๐โ๐ฉ'
- '๐'
- '๐จโโค๏ธโ๐โ๐จ'
- '๐ฉโโค๏ธโ๐โ๐จ'
- '๐ช'
- '๐จโ๐ฉโ๐ฆ'
- '๐จโ๐ฉโ๐ง'
- '๐จโ๐ฉโ๐งโ๐ฆ'
- '๐จโ๐ฉโ๐ฆโ๐ฆ'
- '๐จโ๐ฉโ๐งโ๐ง'
- '๐จโ๐จโ๐ฆ'
- '๐จโ๐จโ๐ง'
- '๐จโ๐จโ๐งโ๐ฆ'
- '๐จโ๐จโ๐ฆโ๐ฆ'
- '๐จโ๐จโ๐งโ๐ง'
- '๐ฉโ๐ฉโ๐ฆ'
- '๐ฉโ๐ฉโ๐ง'
- '๐ฉโ๐ฉโ๐งโ๐ฆ'
- '๐ฉโ๐ฉโ๐ฆโ๐ฆ'
- '๐ฉโ๐ฉโ๐งโ๐ง'
- '๐จโ๐ฆ'
- '๐จโ๐ฆโ๐ฆ'
- '๐จโ๐ง'
- '๐จโ๐งโ๐ฆ'
- '๐จโ๐งโ๐ง'
- '๐ฉโ๐ฆ'
- '๐ฉโ๐ฆโ๐ฆ'
- '๐ฉโ๐ง'
- '๐ฉโ๐งโ๐ฆ'
- '๐ฉโ๐งโ๐ง'
- '๐ฃ'
- '๐ค'
- '๐ฅ'
- '๐ซ'
- '๐งณ'
- '๐'
- 'โ๏ธ'
- '๐งต'
- '๐ชก'
- '๐ชข'
- '๐งถ'
- '๐'
- '๐ถ'
- '๐ฅฝ'
- '๐ฅผ'
- '๐ฆบ'
- '๐'
- '๐'
- '๐'
- '๐งฃ'
- '๐งค'
- '๐งฅ'
- '๐งฆ'
- '๐'
- '๐'
- '๐ฅป'
- '๐ฉด'
- '๐ฉฑ'
- '๐ฉฒ'
- '๐ฉณ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐ฅพ'
- '๐ฅฟ'
- '๐ '
- '๐ก'
- '๐ฉฐ'
- '๐ข'
- '๐'
- '๐'
- '๐ฉ'
- '๐'
- '๐งข'
- 'โ'
- '๐ช'
- '๐'
- '๐'
- '๐ผ'
- '๐๐ป'
- '๐ค๐ป'
- '๐๐ป'
- 'โ๐ป'
- '๐๐ป'
- '๐๐ป'
- '๐ค๐ป'
- '๐ค๐ป'
- 'โ๐ป'
- '๐ค๐ป'
- '๐ซฐ๐ป'
- '๐ค๐ป'
- '๐ค๐ป'
- '๐ค๐ป'
- '๐ซต๐ป'
- '๐ซฑ๐ป'
- '๐ซฒ๐ป'
- '๐ซณ๐ป'
- '๐ซด๐ป'
- '๐๐ป'
- '๐๐ป'
- '๐๐ป'
- '๐๐ป'
- '๐๐ป'
- 'โ๐ป'
- '๐๐ป'
- '๐๐ป'
- 'โ๐ป'
- '๐๐ป'
- '๐ค๐ป'
- '๐ค๐ป'
- '๐๐ป'
- '๐ซถ๐ป'
- '๐๐ป'
- '๐๐ป'
- '๐คฒ๐ป'
- '๐๐ป'
- 'โ๐ป'
- '๐ช๐ป'
- '๐ฆต๐ป'
- '๐ฆถ๐ป'
- '๐๐ป'
- '๐ฆป๐ป'
- '๐๐ป'
- '๐ถ๐ป'
- '๐ง๐ป'
- '๐ง๐ป'
- '๐ฆ๐ป'
- '๐ฉ๐ป'
- '๐ง๐ป'
- '๐จ๐ป'
- '๐ฉ๐ปโ๐ฆฑ'
- '๐ง๐ปโ๐ฆฑ'
- '๐จ๐ปโ๐ฆฑ'
- '๐ฉ๐ปโ๐ฆฐ'
- '๐ง๐ปโ๐ฆฐ'
- '๐จ๐ปโ๐ฆฐ'
- '๐ฑ๐ปโโ๏ธ'
- '๐ฑ๐ป'
- '๐ฑ๐ปโโ๏ธ'
- '๐ฉ๐ปโ๐ฆณ'
- '๐ง๐ปโ๐ฆณ'
- '๐จ๐ปโ๐ฆณ'
- '๐ฉ๐ปโ๐ฆฒ'
- '๐ง๐ปโ๐ฆฒ'
- '๐จ๐ปโ๐ฆฒ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ต๐ป'
- '๐ง๐ป'
- '๐ด๐ป'
- '๐ฒ๐ป'
- '๐ณ๐ปโโ๏ธ'
- '๐ณ๐ป'
- '๐ณ๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ฎ๐ปโโ๏ธ'
- '๐ฎ๐ป'
- '๐ฎ๐ปโโ๏ธ'
- '๐ท๐ปโโ๏ธ'
- '๐ท๐ป'
- '๐ท๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ต๐ปโโ๏ธ'
- '๐ต๐ป'
- '๐ต๐ปโโ๏ธ'
- '๐ฉ๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐จ๐ปโโ๏ธ'
- '๐ฉ๐ปโ๐พ'
- '๐ง๐ปโ๐พ'
- '๐จ๐ปโ๐พ'
- '๐ฉ๐ปโ๐ณ'
- '๐ง๐ปโ๐ณ'
- '๐จ๐ปโ๐ณ'
- '๐ฉ๐ปโ๐'
- '๐ง๐ปโ๐'
- '๐จ๐ปโ๐'
- '๐ฉ๐ปโ๐ค'
- '๐ง๐ปโ๐ค'
- '๐จ๐ปโ๐ค'
- '๐ฉ๐ปโ๐ซ'
- '๐ง๐ปโ๐ซ'
- '๐จ๐ปโ๐ซ'
- '๐ฉ๐ปโ๐ญ'
- '๐ง๐ปโ๐ญ'
- '๐จ๐ปโ๐ญ'
- '๐ฉ๐ปโ๐ป'
- '๐ง๐ปโ๐ป'
- '๐จ๐ปโ๐ป'
- '๐ฉ๐ปโ๐ผ'
- '๐ง๐ปโ๐ผ'
- '๐จ๐ปโ๐ผ'
- '๐ฉ๐ปโ๐ง'
- '๐ง๐ปโ๐ง'
- '๐จ๐ปโ๐ง'
- '๐ฉ๐ปโ๐ฌ'
- '๐ง๐ปโ๐ฌ'
- '๐จ๐ปโ๐ฌ'
- '๐ฉ๐ปโ๐จ'
- '๐ง๐ปโ๐จ'
- '๐จ๐ปโ๐จ'
- '๐ฉ๐ปโ๐'
- '๐ง๐ปโ๐'
- '๐จ๐ปโ๐'
- '๐ฉ๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐จ๐ปโโ๏ธ'
- '๐ฉ๐ปโ๐'
- '๐ง๐ปโ๐'
- '๐จ๐ปโ๐'
- '๐ฉ๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐จ๐ปโโ๏ธ'
- '๐ฐ๐ปโโ๏ธ'
- '๐ฐ๐ป'
- '๐ฐ๐ปโโ๏ธ'
- '๐คต๐ปโโ๏ธ'
- '๐คต๐ป'
- '๐คต๐ปโโ๏ธ'
- '๐ธ๐ป'
- '๐ซ
๐ป'
- '๐คด๐ป'
- '๐ฅท๐ป'
- '๐ฆธ๐ปโโ๏ธ'
- '๐ฆธ๐ป'
- '๐ฆธ๐ปโโ๏ธ'
- '๐ฆน๐ปโโ๏ธ'
- '๐ฆน๐ป'
- '๐ฆน๐ปโโ๏ธ'
- '๐คถ๐ป'
- '๐ง๐ปโ๐'
- '๐
๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ผ๐ป'
- '๐คฐ๐ป'
- '๐ซ๐ป'
- '๐ซ๐ป'
- '๐คฑ๐ป'
- '๐ฉ๐ปโ๐ผ'
- '๐ง๐ปโ๐ผ'
- '๐จ๐ปโ๐ผ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐
๐ปโโ๏ธ'
- '๐
๐ป'
- '๐
๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐คฆ๐ปโโ๏ธ'
- '๐คฆ๐ป'
- '๐คฆ๐ปโโ๏ธ'
- '๐คท๐ปโโ๏ธ'
- '๐คท๐ป'
- '๐คท๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐๐ป'
- '๐บ๐ป'
- '๐ด๐ป'
- '๐ฉ๐ปโ๐ฆฝ'
- '๐ง๐ปโ๐ฆฝ'
- '๐จ๐ปโ๐ฆฝ'
- '๐ฉ๐ปโ๐ฆผ'
- '๐ง๐ปโ๐ฆผ'
- '๐จ๐ปโ๐ฆผ'
- '๐ถ๐ปโโ๏ธ'
- '๐ถ๐ป'
- '๐ถ๐ปโโ๏ธ'
- '๐ฉ๐ปโ๐ฆฏ'
- '๐ง๐ปโ๐ฆฏ'
- '๐จ๐ปโ๐ฆฏ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ญ๐ป'
- '๐ง๐ปโ๐คโ๐ง๐ป'
- '๐ฌ๐ป'
- '๐ซ๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ฃ๐ปโโ๏ธ'
- '๐ฃ๐ป'
- '๐ฃ๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- 'โน๐ปโโ๏ธ'
- 'โน๐ป'
- 'โน๐ปโโ๏ธ'
- '๐๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ปโโ๏ธ'
- '๐ด๐ปโโ๏ธ'
- '๐ด๐ป'
- '๐ด๐ปโโ๏ธ'
- '๐ต๐ปโโ๏ธ'
- '๐ต๐ป'
- '๐ต๐ปโโ๏ธ'
- '๐คธ๐ปโโ๏ธ'
- '๐คธ๐ป'
- '๐คธ๐ปโโ๏ธ'
- '๐คฝ๐ปโโ๏ธ'
- '๐คฝ๐ป'
- '๐คฝ๐ปโโ๏ธ'
- '๐คพ๐ปโโ๏ธ'
- '๐คพ๐ป'
- '๐คพ๐ปโโ๏ธ'
- '๐คน๐ปโโ๏ธ'
- '๐คน๐ป'
- '๐คน๐ปโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ป'
- '๐ง๐ปโโ๏ธ'
- '๐๐ป'
- '๐๐ป'
- '๐๐ผ'
- '๐ค๐ผ'
- '๐๐ผ'
- 'โ๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- '๐ค๐ผ'
- '๐ค๐ผ'
- 'โ๐ผ'
- '๐ค๐ผ'
- '๐ซฐ๐ผ'
- '๐ค๐ผ'
- '๐ค๐ผ'
- '๐ค๐ผ'
- '๐ซต๐ผ'
- '๐ซฑ๐ผ'
- '๐ซฒ๐ผ'
- '๐ซณ๐ผ'
- '๐ซด๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- 'โ๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- 'โ๐ผ'
- '๐๐ผ'
- '๐ค๐ผ'
- '๐ค๐ผ'
- '๐๐ผ'
- '๐ซถ๐ผ'
- '๐๐ผ'
- '๐๐ผ'
- '๐คฒ๐ผ'
- '๐๐ผ'
- 'โ๐ผ'
- '๐ช๐ผ'
- '๐ฆต๐ผ'
- '๐ฆถ๐ผ'
- '๐๐ผ'
- '๐ฆป๐ผ'
- '๐๐ผ'
- '๐ถ๐ผ'
- '๐ง๐ผ'
- '๐ง๐ผ'
- '๐ฆ๐ผ'
- '๐ฉ๐ผ'
- '๐ง๐ผ'
- '๐จ๐ผ'
- '๐ฉ๐ผโ๐ฆฑ'
- '๐ง๐ผโ๐ฆฑ'
- '๐จ๐ผโ๐ฆฑ'
- '๐ฉ๐ผโ๐ฆฐ'
- '๐ง๐ผโ๐ฆฐ'
- '๐จ๐ผโ๐ฆฐ'
- '๐ฑ๐ผโโ๏ธ'
- '๐ฑ๐ผ'
- '๐ฑ๐ผโโ๏ธ'
- '๐ฉ๐ผโ๐ฆณ'
- '๐ง๐ผโ๐ฆณ'
- '๐จ๐ผโ๐ฆณ'
- '๐ฉ๐ผโ๐ฆฒ'
- '๐ง๐ผโ๐ฆฒ'
- '๐จ๐ผโ๐ฆฒ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ต๐ผ'
- '๐ง๐ผ'
- '๐ด๐ผ'
- '๐ฒ๐ผ'
- '๐ณ๐ผโโ๏ธ'
- '๐ณ๐ผ'
- '๐ณ๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ฎ๐ผโโ๏ธ'
- '๐ฎ๐ผ'
- '๐ฎ๐ผโโ๏ธ'
- '๐ท๐ผโโ๏ธ'
- '๐ท๐ผ'
- '๐ท๐ผโโ๏ธ'
- '๐๐ผโโ๏ธ'
- '๐๐ผ'
- '๐๐ผโโ๏ธ'
- '๐ต๐ผโโ๏ธ'
- '๐ต๐ผ'
- '๐ต๐ผโโ๏ธ'
- '๐ฉ๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐จ๐ผโโ๏ธ'
- '๐ฉ๐ผโ๐พ'
- '๐ง๐ผโ๐พ'
- '๐จ๐ผโ๐พ'
- '๐ฉ๐ผโ๐ณ'
- '๐ง๐ผโ๐ณ'
- '๐จ๐ผโ๐ณ'
- '๐ฉ๐ผโ๐'
- '๐ง๐ผโ๐'
- '๐จ๐ผโ๐'
- '๐ฉ๐ผโ๐ค'
- '๐ง๐ผโ๐ค'
- '๐จ๐ผโ๐ค'
- '๐ฉ๐ผโ๐ซ'
- '๐ง๐ผโ๐ซ'
- '๐จ๐ผโ๐ซ'
- '๐ฉ๐ผโ๐ญ'
- '๐ง๐ผโ๐ญ'
- '๐จ๐ผโ๐ญ'
- '๐ฉ๐ผโ๐ป'
- '๐ง๐ผโ๐ป'
- '๐จ๐ผโ๐ป'
- '๐ฉ๐ผโ๐ผ'
- '๐ง๐ผโ๐ผ'
- '๐จ๐ผโ๐ผ'
- '๐ฉ๐ผโ๐ง'
- '๐ง๐ผโ๐ง'
- '๐จ๐ผโ๐ง'
- '๐ฉ๐ผโ๐ฌ'
- '๐ง๐ผโ๐ฌ'
- '๐จ๐ผโ๐ฌ'
- '๐ฉ๐ผโ๐จ'
- '๐ง๐ผโ๐จ'
- '๐จ๐ผโ๐จ'
- '๐ฉ๐ผโ๐'
- '๐ง๐ผโ๐'
- '๐จ๐ผโ๐'
- '๐ฉ๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐จ๐ผโโ๏ธ'
- '๐ฉ๐ผโ๐'
- '๐ง๐ผโ๐'
- '๐จ๐ผโ๐'
- '๐ฉ๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐จ๐ผโโ๏ธ'
- '๐ฐ๐ผโโ๏ธ'
- '๐ฐ๐ผ'
- '๐ฐ๐ผโโ๏ธ'
- '๐คต๐ผโโ๏ธ'
- '๐คต๐ผ'
- '๐คต๐ผโโ๏ธ'
- '๐ธ๐ผ'
- '๐ซ
๐ผ'
- '๐คด๐ผ'
- '๐ฅท๐ผ'
- '๐ฆธ๐ผโโ๏ธ'
- '๐ฆธ๐ผ'
- '๐ฆธ๐ผโโ๏ธ'
- '๐ฆน๐ผโโ๏ธ'
- '๐ฆน๐ผ'
- '๐ฆน๐ผโโ๏ธ'
- '๐คถ๐ผ'
- '๐ง๐ผโ๐'
- '๐
๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐ผ๐ผ'
- '๐คฐ๐ผ'
- '๐ซ๐ผ'
- '๐ซ๐ผ'
- '๐คฑ๐ผ'
- '๐ฉ๐ผโ๐ผ'
- '๐ง๐ผโ๐ผ'
- '๐จ๐ผโ๐ผ'
- '๐๐ผโโ๏ธ'
- '๐๐ผ'
- '๐๐ผโโ๏ธ'
- '๐๐ผโโ๏ธ'
- '๐๐ผ'
- '๐๐ผโโ๏ธ'
- '๐
๐ผโโ๏ธ'
- '๐
๐ผ'
- '๐
๐ผโโ๏ธ'
- '๐๐ผโโ๏ธ'
- '๐๐ผ'
- '๐๐ผโโ๏ธ'
- '๐๐ผโโ๏ธ'
- '๐๐ผ'
- '๐๐ผโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ผ'
- '๐ง๐ผโโ๏ธ'
- '๐คฆ๐ผโโ๏ธ'
- '๐คฆ๐ผ'
- '๐คฆ๐ผโโ๏ธ'
- '๐คท๐ผโโ๏ธ'
condition: selection
falsepositives:
- Unknown
level: high
imProcessCreate
| where TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐คฃ" or TargetProcessCommandLine contains "๐ฅฒ" or TargetProcessCommandLine contains "๐ฅน" or TargetProcessCommandLine contains "โบ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฅฐ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐คช" or TargetProcessCommandLine contains "๐คจ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฅธ" or TargetProcessCommandLine contains "๐คฉ" or TargetProcessCommandLine contains "๐ฅณ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โน๏ธ" or TargetProcessCommandLine contains "๐ฃ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐ฅบ" or TargetProcessCommandLine contains "๐ข" or TargetProcessCommandLine contains "๐ญ" or TargetProcessCommandLine contains "๐ฎโ๐จ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ " or TargetProcessCommandLine contains "๐ก" or TargetProcessCommandLine contains "๐คฌ" or TargetProcessCommandLine contains "๐คฏ" or TargetProcessCommandLine contains "๐ณ" or TargetProcessCommandLine contains "๐ฅต" or TargetProcessCommandLine contains "๐ฅถ" or TargetProcessCommandLine contains "๐ฑ" or TargetProcessCommandLine contains "๐จ" or TargetProcessCommandLine contains "๐ฐ" or TargetProcessCommandLine contains "๐ฅ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ซฃ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ซก" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ซข" or TargetProcessCommandLine contains "๐คญ" or TargetProcessCommandLine contains "๐คซ" or TargetProcessCommandLine contains "๐คฅ" or TargetProcessCommandLine contains "๐ถ" or TargetProcessCommandLine contains "๐ถโ๐ซ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฌ" or TargetProcessCommandLine contains "๐ซ " or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฏ" or TargetProcessCommandLine contains "๐ฆ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ฎ" or TargetProcessCommandLine contains "๐ฒ" or TargetProcessCommandLine contains "๐ฅฑ" or TargetProcessCommandLine contains "๐ด" or TargetProcessCommandLine contains "๐คค" or TargetProcessCommandLine contains "๐ช" or TargetProcessCommandLine contains "๐ต" or TargetProcessCommandLine contains "๐ตโ๐ซ" or TargetProcessCommandLine contains "๐ซฅ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ฅด" or TargetProcessCommandLine contains "๐คข" or TargetProcessCommandLine contains "๐คฎ" or TargetProcessCommandLine contains "๐คง" or TargetProcessCommandLine contains "๐ท" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค " or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฟ" or TargetProcessCommandLine contains "๐น" or TargetProcessCommandLine contains "๐บ" or TargetProcessCommandLine contains "๐คก" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐ป" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ ๏ธ" or TargetProcessCommandLine contains "๐ฝ" or TargetProcessCommandLine contains "๐พ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐บ" or TargetProcessCommandLine contains "๐ธ" or TargetProcessCommandLine contains "๐น" or TargetProcessCommandLine contains "๐ป" or TargetProcessCommandLine contains "๐ผ" or TargetProcessCommandLine contains "๐ฝ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฟ" or TargetProcessCommandLine contains "๐พ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "โ๏ธ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ซฐ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ซต" or TargetProcessCommandLine contains "๐ซฑ" or TargetProcessCommandLine contains "๐ซฒ" or TargetProcessCommandLine contains "๐ซณ" or TargetProcessCommandLine contains "๐ซด" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ซถ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐คฒ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ๏ธ" or TargetProcessCommandLine contains "๐ช" or TargetProcessCommandLine contains "๐ฆพ" or TargetProcessCommandLine contains "๐ฆต" or TargetProcessCommandLine contains "๐ฆฟ" or TargetProcessCommandLine contains "๐ฆถ" or TargetProcessCommandLine contains "๐ฃ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฆป" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ง " or TargetProcessCommandLine contains "๐ฆท" or TargetProcessCommandLine contains "๐ฆด" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ซฆ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฉธ" or TargetProcessCommandLine contains "๐ถ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ฆ" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐จ" or TargetProcessCommandLine contains "๐ฉโ๐ฆฑ" or TargetProcessCommandLine contains "๐งโ๐ฆฑ" or TargetProcessCommandLine contains "๐จโ๐ฆฑ" or TargetProcessCommandLine contains "๐ฉโ๐ฆฐ" or TargetProcessCommandLine contains "๐งโ๐ฆฐ" or TargetProcessCommandLine contains "๐จโ๐ฆฐ" or TargetProcessCommandLine contains "๐ฑโโ๏ธ" or TargetProcessCommandLine contains "๐ฑ" or TargetProcessCommandLine contains "๐ฑโโ๏ธ" or TargetProcessCommandLine contains "๐ฉโ๐ฆณ" or TargetProcessCommandLine contains "๐งโ๐ฆณ" or TargetProcessCommandLine contains "๐จโ๐ฆณ" or TargetProcessCommandLine contains "๐ฉโ๐ฆฒ" or TargetProcessCommandLine contains "๐งโ๐ฆฒ" or TargetProcessCommandLine contains "๐จโ๐ฆฒ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ต" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ด" or TargetProcessCommandLine contains "๐ฒ" or TargetProcessCommandLine contains "๐ณโโ๏ธ" or TargetProcessCommandLine contains "๐ณ" or TargetProcessCommandLine contains "๐ณโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ฎโโ๏ธ" or TargetProcessCommandLine contains "๐ฎ" or TargetProcessCommandLine contains "๐ฎโโ๏ธ" or TargetProcessCommandLine contains "๐ทโโ๏ธ" or TargetProcessCommandLine contains "๐ท" or TargetProcessCommandLine contains "๐ทโโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐ต๏ธโโ๏ธ" or TargetProcessCommandLine contains "๐ต๏ธ" or TargetProcessCommandLine contains "๐ต๏ธโโ๏ธ" or TargetProcessCommandLine contains "๐ฉโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐จโโ๏ธ" or TargetProcessCommandLine contains "๐ฉโ๐พ" or TargetProcessCommandLine contains "๐งโ๐พ" or TargetProcessCommandLine contains "๐จโ๐พ" or TargetProcessCommandLine contains "๐ฉโ๐ณ" or TargetProcessCommandLine contains "๐งโ๐ณ" or TargetProcessCommandLine contains "๐จโ๐ณ" or TargetProcessCommandLine contains "๐ฉโ๐" or TargetProcessCommandLine contains "๐งโ๐" or TargetProcessCommandLine contains "๐จโ๐" or TargetProcessCommandLine contains "๐ฉโ๐ค" or TargetProcessCommandLine contains "๐งโ๐ค" or TargetProcessCommandLine contains "๐จโ๐ค" or TargetProcessCommandLine contains "๐ฉโ๐ซ" or TargetProcessCommandLine contains "๐งโ๐ซ" or TargetProcessCommandLine contains "๐จโ๐ซ" or TargetProcessCommandLine contains "๐ฉโ๐ญ" or TargetProcessCommandLine contains "๐งโ๐ญ" or TargetProcessCommandLine contains "๐จโ๐ญ" or TargetProcessCommandLine contains "๐ฉโ๐ป" or TargetProcessCommandLine contains "๐งโ๐ป" or TargetProcessCommandLine contains "๐จโ๐ป" or TargetProcessCommandLine contains "๐ฉโ๐ผ" or TargetProcessCommandLine contains "๐งโ๐ผ" or TargetProcessCommandLine contains "๐จโ๐ผ" or TargetProcessCommandLine contains "๐ฉโ๐ง" or TargetProcessCommandLine contains "๐งโ๐ง" or TargetProcessCommandLine contains "๐จโ๐ง" or TargetProcessCommandLine contains "๐ฉโ๐ฌ" or TargetProcessCommandLine contains "๐งโ๐ฌ" or TargetProcessCommandLine contains "๐จโ๐ฌ" or TargetProcessCommandLine contains "๐ฉโ๐จ" or TargetProcessCommandLine contains "๐งโ๐จ" or TargetProcessCommandLine contains "๐จโ๐จ" or TargetProcessCommandLine contains "๐ฉโ๐" or TargetProcessCommandLine contains "๐งโ๐" or TargetProcessCommandLine contains "๐จโ๐" or TargetProcessCommandLine contains "๐ฉโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐จโโ๏ธ" or TargetProcessCommandLine contains "๐ฉโ๐" or TargetProcessCommandLine contains "๐งโ๐" or TargetProcessCommandLine contains "๐จโ๐" or TargetProcessCommandLine contains "๐ฉโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐จโโ๏ธ" or TargetProcessCommandLine contains "๐ฐโโ๏ธ" or TargetProcessCommandLine contains "๐ฐ" or TargetProcessCommandLine contains "๐ฐโโ๏ธ" or TargetProcessCommandLine contains "๐คตโโ๏ธ" or TargetProcessCommandLine contains "๐คต" or TargetProcessCommandLine contains "๐คตโโ๏ธ" or TargetProcessCommandLine contains "๐ธ" or TargetProcessCommandLine contains "๐ซ
" or TargetProcessCommandLine contains "๐คด" or TargetProcessCommandLine contains "๐ฅท" or TargetProcessCommandLine contains "๐ฆธโโ๏ธ" or TargetProcessCommandLine contains "๐ฆธ" or TargetProcessCommandLine contains "๐ฆธโโ๏ธ" or TargetProcessCommandLine contains "๐ฆนโโ๏ธ" or TargetProcessCommandLine contains "๐ฆน" or TargetProcessCommandLine contains "๐ฆนโโ๏ธ" or TargetProcessCommandLine contains "๐คถ" or TargetProcessCommandLine contains "๐งโ๐" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ผ" or TargetProcessCommandLine contains "๐คฐ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐คฑ" or TargetProcessCommandLine contains "๐ฉโ๐ผ" or TargetProcessCommandLine contains "๐งโ๐ผ" or TargetProcessCommandLine contains "๐จโ๐ผ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐
โโ๏ธ" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐
โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐คฆโโ๏ธ" or TargetProcessCommandLine contains "๐คฆ" or TargetProcessCommandLine contains "๐คฆโโ๏ธ" or TargetProcessCommandLine contains "๐คทโโ๏ธ" or TargetProcessCommandLine contains "๐คท" or TargetProcessCommandLine contains "๐คทโโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐บ" or TargetProcessCommandLine contains "๐ฏโโ๏ธ" or TargetProcessCommandLine contains "๐ฏ" or TargetProcessCommandLine contains "๐ฏโโ๏ธ" or TargetProcessCommandLine contains "๐ด" or TargetProcessCommandLine contains "๐ฉโ๐ฆฝ" or TargetProcessCommandLine contains "๐งโ๐ฆฝ" or TargetProcessCommandLine contains "๐จโ๐ฆฝ" or TargetProcessCommandLine contains "๐ฉโ๐ฆผ" or TargetProcessCommandLine contains "๐งโ๐ฆผ" or TargetProcessCommandLine contains "๐จโ๐ฆผ" or TargetProcessCommandLine contains "๐ถโโ๏ธ" or TargetProcessCommandLine contains "๐ถ" or TargetProcessCommandLine contains "๐ถโโ๏ธ" or TargetProcessCommandLine contains "๐ฉโ๐ฆฏ" or TargetProcessCommandLine contains "๐งโ๐ฆฏ" or TargetProcessCommandLine contains "๐จโ๐ฆฏ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐โโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ญ" or TargetProcessCommandLine contains "๐งโ๐คโ๐ง" or TargetProcessCommandLine contains "๐ฌ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ฉโโค๏ธโ๐ฉ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐จโโค๏ธโ๐จ" or TargetProcessCommandLine contains "๐ฉโโค๏ธโ๐จ" or TargetProcessCommandLine contains "๐ฉโโค๏ธโ๐โ๐ฉ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐จโโค๏ธโ๐โ๐จ" or TargetProcessCommandLine contains "๐ฉโโค๏ธโ๐โ๐จ" or TargetProcessCommandLine contains "๐ช" or TargetProcessCommandLine contains "๐จโ๐ฉโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐ฉโ๐ง" or TargetProcessCommandLine contains "๐จโ๐ฉโ๐งโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐ฉโ๐ฆโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐ฉโ๐งโ๐ง" or TargetProcessCommandLine contains "๐จโ๐จโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐จโ๐ง" or TargetProcessCommandLine contains "๐จโ๐จโ๐งโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐จโ๐ฆโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐จโ๐งโ๐ง" or TargetProcessCommandLine contains "๐ฉโ๐ฉโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐ฉโ๐ง" or TargetProcessCommandLine contains "๐ฉโ๐ฉโ๐งโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐ฉโ๐ฆโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐ฉโ๐งโ๐ง" or TargetProcessCommandLine contains "๐จโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐ฆโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐ง" or TargetProcessCommandLine contains "๐จโ๐งโ๐ฆ" or TargetProcessCommandLine contains "๐จโ๐งโ๐ง" or TargetProcessCommandLine contains "๐ฉโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐ฆโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐ง" or TargetProcessCommandLine contains "๐ฉโ๐งโ๐ฆ" or TargetProcessCommandLine contains "๐ฉโ๐งโ๐ง" or TargetProcessCommandLine contains "๐ฃ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ฅ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐งณ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "โ๏ธ" or TargetProcessCommandLine contains "๐งต" or TargetProcessCommandLine contains "๐ชก" or TargetProcessCommandLine contains "๐ชข" or TargetProcessCommandLine contains "๐งถ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ถ" or TargetProcessCommandLine contains "๐ฅฝ" or TargetProcessCommandLine contains "๐ฅผ" or TargetProcessCommandLine contains "๐ฆบ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐งฃ" or TargetProcessCommandLine contains "๐งค" or TargetProcessCommandLine contains "๐งฅ" or TargetProcessCommandLine contains "๐งฆ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฅป" or TargetProcessCommandLine contains "๐ฉด" or TargetProcessCommandLine contains "๐ฉฑ" or TargetProcessCommandLine contains "๐ฉฒ" or TargetProcessCommandLine contains "๐ฉณ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฅพ" or TargetProcessCommandLine contains "๐ฅฟ" or TargetProcessCommandLine contains "๐ " or TargetProcessCommandLine contains "๐ก" or TargetProcessCommandLine contains "๐ฉฐ" or TargetProcessCommandLine contains "๐ข" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐งข" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "๐ช" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ผ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "โ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "โ๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ซฐ๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ซต๐ป" or TargetProcessCommandLine contains "๐ซฑ๐ป" or TargetProcessCommandLine contains "๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซณ๐ป" or TargetProcessCommandLine contains "๐ซด๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "โ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "โ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ซถ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐คฒ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "โ๐ป" or TargetProcessCommandLine contains "๐ช๐ป" or TargetProcessCommandLine contains "๐ฆต๐ป" or TargetProcessCommandLine contains "๐ฆถ๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ฆป๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐ถ๐ป" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ฆ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ป" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆฑ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆฑ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆฑ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆฐ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆฐ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆฐ" or TargetProcessCommandLine contains "๐ฑ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฑ๐ป" or TargetProcessCommandLine contains "๐ฑ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆณ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆณ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆณ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆฒ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆฒ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆฒ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ป" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ด๐ป" or TargetProcessCommandLine contains "๐ฒ๐ป" or TargetProcessCommandLine contains "๐ณ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ณ๐ป" or TargetProcessCommandLine contains "๐ณ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ฎ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฎ๐ป" or TargetProcessCommandLine contains "๐ฎ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ท๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ท๐ป" or TargetProcessCommandLine contains "๐ท๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ป" or TargetProcessCommandLine contains "๐ต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐พ" or TargetProcessCommandLine contains "๐ง๐ปโ๐พ" or TargetProcessCommandLine contains "๐จ๐ปโ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ณ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ณ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ณ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐" or TargetProcessCommandLine contains "๐ง๐ปโ๐" or TargetProcessCommandLine contains "๐จ๐ปโ๐" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ค" or TargetProcessCommandLine contains "๐ง๐ปโ๐ค" or TargetProcessCommandLine contains "๐จ๐ปโ๐ค" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ซ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ซ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ซ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ญ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ญ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ญ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ป" or TargetProcessCommandLine contains "๐ง๐ปโ๐ป" or TargetProcessCommandLine contains "๐จ๐ปโ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ผ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ผ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ง" or TargetProcessCommandLine contains "๐ง๐ปโ๐ง" or TargetProcessCommandLine contains "๐จ๐ปโ๐ง" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฌ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฌ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฌ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐จ" or TargetProcessCommandLine contains "๐ง๐ปโ๐จ" or TargetProcessCommandLine contains "๐จ๐ปโ๐จ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐" or TargetProcessCommandLine contains "๐ง๐ปโ๐" or TargetProcessCommandLine contains "๐จ๐ปโ๐" or TargetProcessCommandLine contains "๐ฉ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐" or TargetProcessCommandLine contains "๐ง๐ปโ๐" or TargetProcessCommandLine contains "๐จ๐ปโ๐" or TargetProcessCommandLine contains "๐ฉ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฐ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฐ๐ป" or TargetProcessCommandLine contains "๐ฐ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คต๐ป" or TargetProcessCommandLine contains "๐คต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ธ๐ป" or TargetProcessCommandLine contains "๐ซ
๐ป" or TargetProcessCommandLine contains "๐คด๐ป" or TargetProcessCommandLine contains "๐ฅท๐ป" or TargetProcessCommandLine contains "๐ฆธ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฆธ๐ป" or TargetProcessCommandLine contains "๐ฆธ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฆน๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฆน๐ป" or TargetProcessCommandLine contains "๐ฆน๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คถ๐ป" or TargetProcessCommandLine contains "๐ง๐ปโ๐" or TargetProcessCommandLine contains "๐
๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ผ๐ป" or TargetProcessCommandLine contains "๐คฐ๐ป" or TargetProcessCommandLine contains "๐ซ๐ป" or TargetProcessCommandLine contains "๐ซ๐ป" or TargetProcessCommandLine contains "๐คฑ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ผ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ผ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ผ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐
๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐
๐ป" or TargetProcessCommandLine contains "๐
๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คฆ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คฆ๐ป" or TargetProcessCommandLine contains "๐คฆ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คท๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คท๐ป" or TargetProcessCommandLine contains "๐คท๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐บ๐ป" or TargetProcessCommandLine contains "๐ด๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆฝ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆฝ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆฝ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆผ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆผ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆผ" or TargetProcessCommandLine contains "๐ถ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ถ๐ป" or TargetProcessCommandLine contains "๐ถ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ปโ๐ฆฏ" or TargetProcessCommandLine contains "๐ง๐ปโ๐ฆฏ" or TargetProcessCommandLine contains "๐จ๐ปโ๐ฆฏ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ญ๐ป" or TargetProcessCommandLine contains "๐ง๐ปโ๐คโ๐ง๐ป" or TargetProcessCommandLine contains "๐ฌ๐ป" or TargetProcessCommandLine contains "๐ซ๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฃ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ฃ๐ป" or TargetProcessCommandLine contains "๐ฃ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "โน๐ปโโ๏ธ" or TargetProcessCommandLine contains "โน๐ป" or TargetProcessCommandLine contains "โน๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ด๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ด๐ป" or TargetProcessCommandLine contains "๐ด๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ป" or TargetProcessCommandLine contains "๐ต๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คธ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คธ๐ป" or TargetProcessCommandLine contains "๐คธ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คฝ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คฝ๐ป" or TargetProcessCommandLine contains "๐คฝ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คพ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คพ๐ป" or TargetProcessCommandLine contains "๐คพ๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คน๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐คน๐ป" or TargetProcessCommandLine contains "๐คน๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "โ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "โ๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ซฐ๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ซต๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐ผ" or TargetProcessCommandLine contains "๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซณ๐ผ" or TargetProcessCommandLine contains "๐ซด๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "โ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "โ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ซถ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐คฒ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "โ๐ผ" or TargetProcessCommandLine contains "๐ช๐ผ" or TargetProcessCommandLine contains "๐ฆต๐ผ" or TargetProcessCommandLine contains "๐ฆถ๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ฆป๐ผ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐ถ๐ผ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ฆ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ฆฑ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ฆฑ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ฆฑ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ฆฐ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ฆฐ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ฆฐ" or TargetProcessCommandLine contains "๐ฑ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฑ๐ผ" or TargetProcessCommandLine contains "๐ฑ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ฆณ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ฆณ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ฆณ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ฆฒ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ฆฒ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ฆฒ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ผ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ด๐ผ" or TargetProcessCommandLine contains "๐ฒ๐ผ" or TargetProcessCommandLine contains "๐ณ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ณ๐ผ" or TargetProcessCommandLine contains "๐ณ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ฎ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฎ๐ผ" or TargetProcessCommandLine contains "๐ฎ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ท๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ท๐ผ" or TargetProcessCommandLine contains "๐ท๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ต๐ผ" or TargetProcessCommandLine contains "๐ต๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐พ" or TargetProcessCommandLine contains "๐ง๐ผโ๐พ" or TargetProcessCommandLine contains "๐จ๐ผโ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ณ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ณ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ณ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐" or TargetProcessCommandLine contains "๐ง๐ผโ๐" or TargetProcessCommandLine contains "๐จ๐ผโ๐" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ค" or TargetProcessCommandLine contains "๐ง๐ผโ๐ค" or TargetProcessCommandLine contains "๐จ๐ผโ๐ค" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ซ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ซ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ซ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ญ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ญ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ญ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ป" or TargetProcessCommandLine contains "๐ง๐ผโ๐ป" or TargetProcessCommandLine contains "๐จ๐ผโ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ผ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ง" or TargetProcessCommandLine contains "๐ง๐ผโ๐ง" or TargetProcessCommandLine contains "๐จ๐ผโ๐ง" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ฌ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ฌ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ฌ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐จ" or TargetProcessCommandLine contains "๐ง๐ผโ๐จ" or TargetProcessCommandLine contains "๐จ๐ผโ๐จ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐" or TargetProcessCommandLine contains "๐ง๐ผโ๐" or TargetProcessCommandLine contains "๐จ๐ผโ๐" or TargetProcessCommandLine contains "๐ฉ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐" or TargetProcessCommandLine contains "๐ง๐ผโ๐" or TargetProcessCommandLine contains "๐จ๐ผโ๐" or TargetProcessCommandLine contains "๐ฉ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐จ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฐ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฐ๐ผ" or TargetProcessCommandLine contains "๐ฐ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คต๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คต๐ผ" or TargetProcessCommandLine contains "๐คต๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ธ๐ผ" or TargetProcessCommandLine contains "๐ซ
๐ผ" or TargetProcessCommandLine contains "๐คด๐ผ" or TargetProcessCommandLine contains "๐ฅท๐ผ" or TargetProcessCommandLine contains "๐ฆธ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฆธ๐ผ" or TargetProcessCommandLine contains "๐ฆธ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฆน๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ฆน๐ผ" or TargetProcessCommandLine contains "๐ฆน๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คถ๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโ๐" or TargetProcessCommandLine contains "๐
๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ผ๐ผ" or TargetProcessCommandLine contains "๐คฐ๐ผ" or TargetProcessCommandLine contains "๐ซ๐ผ" or TargetProcessCommandLine contains "๐ซ๐ผ" or TargetProcessCommandLine contains "๐คฑ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโ๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโ๐ผ" or TargetProcessCommandLine contains "๐จ๐ผโ๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐
๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐
๐ผ" or TargetProcessCommandLine contains "๐
๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คฆ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คฆ๐ผ" or TargetProcessCommandLine contains "๐คฆ๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐คท๐ผโโ๏ธ"
| Sentinel Table | Notes |
|---|---|
imProcessCreate | Ensure this data connector is enabled |