Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
title: Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4
id: 225274c4-8dd1-40db-9e09-71dff4f6fb3c
status: test
description: Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.
author: '@Kostastsale, TheDFIRReport'
references:
- Internal Research
tags:
- attack.stealth
date: 2022-12-05
logsource:
product: windows
category: process_creation
detection:
selection:
CommandLine|contains:
- '๐ธ'
- '๐น'
- '๐ถ'
- '๐ท'
- '๐ณ'
- '๐ฒ'
- 'โช๏ธ'
- 'โซ๏ธ'
- 'โพ๏ธ'
- 'โฝ๏ธ'
- 'โผ๏ธ'
- 'โป๏ธ'
- '๐ฅ'
- '๐ง'
- '๐จ'
- '๐ฉ'
- '๐ฆ'
- '๐ช'
- 'โฌ๏ธ'
- 'โฌ๏ธ'
- '๐ซ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐ฃ'
- '๐ข'
- '๐โ๐จ'
- '๐ฌ'
- '๐ญ'
- '๐ฏ'
- 'โ ๏ธ'
- 'โฃ๏ธ'
- 'โฅ๏ธ'
- 'โฆ๏ธ'
- '๐'
- '๐ด'
- '๐๏ธ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐ '
- '๐ก'
- '๐ข'
- '๐ฃ'
- '๐ค'
- '๐ฅ'
- '๐ฆ'
- '๐งโข'
- 'โฃ'
- 'โค'
- 'โฅ'
- 'โฆ'
- 'โง'
- 'โ
'
- 'โ'
- 'โฏ'
- 'โก๏ธ'
- 'โฉ'
- 'โช'
- 'โซ'
- 'โฌ'
- 'โญ'
- 'โฎ'
- 'โถ'
- 'โท'
- 'โต'
- 'โธ'
- 'โน'
- 'โ'
- 'โ'
- 'โน'
- 'โจ'
- 'โพ'
- 'โพ'
- 'โข'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ ๏ธ'
- 'โฃ๏ธ'
- 'โฅ๏ธ'
- 'โฆ๏ธ'
- 'โค'
- 'โง'
- 'โก'
- 'โข'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- 'โ
'
- '๐ '
- 'โ'
- 'โ'
- 'โ'
- 'โ'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐
'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐'
- '๐๐ณ๏ธ'
- '๐ด'
- '๐'
- '๐ฉ'
- '๐ณ๏ธโ๐'
- '๐ณ๏ธโโง๏ธ'
- '๐ดโโ ๏ธ'
- '๐ฆ๐ซ'
- '๐ฆ๐ฝ'
- '๐ฆ๐ฑ'
- '๐ฉ๐ฟ'
- '๐ฆ๐ธ'
- '๐ฆ๐ฉ'
- '๐ฆ๐ด'
- '๐ฆ๐ฎ'
- '๐ฆ๐ถ'
- '๐ฆ๐ฌ'
- '๐ฆ๐ท'
- '๐ฆ๐ฒ'
- '๐ฆ๐ผ'
- '๐ฆ๐บ'
- '๐ฆ๐น'
- '๐ฆ๐ฟ'
- '๐ง๐ธ'
- '๐ง๐ญ'
- '๐ง๐ฉ'
- '๐ง๐ง'
- '๐ง๐พ'
- '๐ง๐ช'
- '๐ง๐ฟ'
- '๐ง๐ฏ'
- '๐ง๐ฒ'
- '๐ง๐น'
- '๐ง๐ด'
- '๐ง๐ฆ'
- '๐ง๐ผ'
- '๐ง๐ท'
- '๐ฎ๐ด'
- '๐ป๐ฌ'
- '๐ง๐ณ'
- '๐ง๐ฌ'
- '๐ง๐ซ'
- '๐ง๐ฎ'
- '๐ฐ๐ญ'
- '๐จ๐ฒ'
- '๐จ๐ฆ'
- '๐ฎ๐จ'
- '๐จ๐ป'
- '๐ง๐ถ'
- '๐ฐ๐พ'
- '๐จ๐ซ'
- '๐น๐ฉ'
- '๐จ๐ฑ'
- '๐จ๐ณ'
- '๐จ๐ฝ'
- '๐จ๐จ'
- '๐จ๐ด'
- '๐ฐ๐ฒ'
- '๐จ๐ฌ'
- '๐จ๐ฉ'
- '๐จ๐ฐ'
- '๐จ๐ท'
- '๐จ๐ฎ'
- '๐ญ๐ท'
- '๐จ๐บ'
- '๐จ๐ผ'
- '๐จ๐พ'
- '๐จ๐ฟ'
- '๐ฉ๐ฐ'
- '๐ฉ๐ฏ'
- '๐ฉ๐ฒ'
- '๐ฉ๐ด'
- '๐ช๐จ'
- '๐ช๐ฌ'
- '๐ธ๐ป'
- '๐ฌ๐ถ'
- '๐ช๐ท'
- '๐ช๐ช'
- '๐ช๐น'
- '๐ช๐บ'
- '๐ซ๐ฐ'
- '๐ซ๐ด'
- '๐ซ๐ฏ'
- '๐ซ๐ฎ'
- '๐ซ๐ท'
- '๐ฌ๐ซ'
- '๐ต๐ซ'
- '๐น๐ซ'
- '๐ฌ๐ฆ'
- '๐ฌ๐ฒ'
- '๐ฌ๐ช'
- '๐ฉ๐ช'
- '๐ฌ๐ญ'
- '๐ฌ๐ฎ'
- '๐ฌ๐ท'
- '๐ฌ๐ฑ'
- '๐ฌ๐ฉ'
- '๐ฌ๐ต'
- '๐ฌ๐บ'
- '๐ฌ๐น'
- '๐ฌ๐ฌ'
- '๐ฌ๐ณ'
- '๐ฌ๐ผ'
- '๐ฌ๐พ'
- '๐ญ๐น'
- '๐ญ๐ณ'
- '๐ญ๐ฐ'
- '๐ญ๐บ'
- '๐ฎ๐ธ'
- '๐ฎ๐ณ'
- '๐ฎ๐ฉ'
- '๐ฎ๐ท'
- '๐ฎ๐ถ'
- '๐ฎ๐ช'
- '๐ฎ๐ฒ'
- '๐ฎ๐ฑ'
- '๐ฎ๐น'
- '๐ฏ๐ฒ'
- '๐ฏ๐ต'
- '๐'
- '๐ฏ๐ช'
- '๐ฏ๐ด'
- '๐ฐ๐ฟ'
- '๐ฐ๐ช'
- '๐ฐ๐ฎ'
- '๐ฝ๐ฐ'
- '๐ฐ๐ผ'
- '๐ฐ๐ฌ'
- '๐ฑ๐ฆ'
- '๐ฑ๐ป'
- '๐ฑ๐ง'
- '๐ฑ๐ธ'
- '๐ฑ๐ท'
- '๐ฑ๐พ'
- '๐ฑ๐ฎ'
- '๐ฑ๐น'
- '๐ฑ๐บ'
- '๐ฒ๐ด'
- '๐ฒ๐ฐ'
- '๐ฒ๐ฌ'
- '๐ฒ๐ผ'
- '๐ฒ๐พ'
- '๐ฒ๐ป'
- '๐ฒ๐ฑ'
- '๐ฒ๐น'
- '๐ฒ๐ญ'
- '๐ฒ๐ถ'
- '๐ฒ๐ท'
- '๐ฒ๐บ'
- '๐พ๐น'
- '๐ฒ๐ฝ'
- '๐ซ๐ฒ'
- '๐ฒ๐ฉ'
- '๐ฒ๐จ'
- '๐ฒ๐ณ'
- '๐ฒ๐ช'
- '๐ฒ๐ธ'
- '๐ฒ๐ฆ'
- '๐ฒ๐ฟ'
- '๐ฒ๐ฒ'
- '๐ณ๐ฆ'
- '๐ณ๐ท'
- '๐ณ๐ต'
- '๐ณ๐ฑ'
- '๐ณ๐จ'
- '๐ณ๐ฟ'
- '๐ณ๐ฎ'
- '๐ณ๐ช'
- '๐ณ๐ฌ'
- '๐ณ๐บ'
- '๐ณ๐ซ'
- '๐ฐ๐ต'
- '๐ฒ๐ต'
- '๐ณ๐ด'
- '๐ด๐ฒ'
- '๐ต๐ฐ'
- '๐ต๐ผ'
- '๐ต๐ธ'
- '๐ต๐ฆ'
- '๐ต๐ฌ'
- '๐ต๐พ'
- '๐ต๐ช'
- '๐ต๐ญ'
- '๐ต๐ณ'
- '๐ต๐ฑ'
- '๐ต๐น'
- '๐ต๐ท'
- '๐ถ๐ฆ'
- '๐ท๐ช'
- '๐ท๐ด'
- '๐ท๐บ'
- '๐ท๐ผ'
- '๐ผ๐ธ'
- '๐ธ๐ฒ'
- '๐ธ๐ฆ'
- '๐ธ๐ณ'
- '๐ท๐ธ'
- '๐ธ๐จ'
- '๐ธ๐ฑ'
- '๐ธ๐ฌ'
- '๐ธ๐ฝ'
- '๐ธ๐ฐ'
- '๐ธ๐ฎ'
- '๐ฌ๐ธ'
- '๐ธ๐ง'
- '๐ธ๐ด'
- '๐ฟ๐ฆ'
- '๐ฐ๐ท'
- '๐ธ๐ธ'
- '๐ช๐ธ'
- '๐ฑ๐ฐ'
- '๐ง๐ฑ'
- '๐ธ๐ญ'
- '๐ฐ๐ณ'
- '๐ฑ๐จ'
- '๐ต๐ฒ'
- '๐ป๐จ'
- '๐ธ๐ฉ'
- '๐ธ๐ท'
- '๐ธ๐ฟ'
- '๐ธ๐ช'
- '๐จ๐ญ'
- '๐ธ๐พ'
- '๐น๐ผ'
- '๐น๐ฏ'
- '๐น๐ฟ'
- '๐น๐ญ'
- '๐น๐ฑ'
- '๐น๐ฌ'
- '๐น๐ฐ'
- '๐น๐ด'
- '๐น๐น'
- '๐น๐ณ'
- '๐น๐ท'
- '๐น๐ฒ'
- '๐น๐จ'
- '๐น๐ป'
- '๐ป๐ฎ'
- '๐บ๐ฌ'
- '๐บ๐ฆ'
- '๐ฆ๐ช'
- '๐ฌ๐ง'
- '๐ด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ'
- '๐ด๓ ง๓ ข๓ ณ๓ ฃ๓ ด๓ ฟ'
- '๐ด๓ ง๓ ข๓ ท๓ ฌ๓ ณ๓ ฟ'
- '๐บ๐ณ'
- '๐บ๐ธ'
- '๐บ๐พ'
- '๐บ๐ฟ'
- '๐ป๐บ'
- '๐ป๐ฆ'
- '๐ป๐ช'
- '๐ป๐ณ'
- '๐ผ๐ซ'
- '๐ช๐ญ'
- '๐พ๐ช'
- '๐ฟ๐ฒ'
- '๐ฟ๐ผ๐ซ '
- '๐ซข'
- '๐ซฃ'
- '๐ซก'
- '๐ซฅ'
- '๐ซค'
- '๐ฅน'
- '๐ซฑ'
- '๐ซฑ๐ป'
- '๐ซฑ๐ผ'
- '๐ซฑ๐ฝ'
- '๐ซฑ๐พ'
- '๐ซฑ๐ฟ'
- '๐ซฒ'
- '๐ซฒ๐ป'
- '๐ซฒ๐ผ'
- '๐ซฒ๐ฝ'
- '๐ซฒ๐พ'
- '๐ซฒ๐ฟ'
- '๐ซณ'
- '๐ซณ๐ป'
- '๐ซณ๐ผ'
- '๐ซณ๐ฝ'
- '๐ซณ๐พ'
- '๐ซณ๐ฟ'
- '๐ซด'
- '๐ซด๐ป'
- '๐ซด๐ผ'
- '๐ซด๐ฝ'
- '๐ซด๐พ'
- '๐ซด๐ฟ'
- '๐ซฐ'
- '๐ซฐ๐ป'
- '๐ซฐ๐ผ'
- '๐ซฐ๐ฝ'
- '๐ซฐ๐พ'
- '๐ซฐ๐ฟ'
- '๐ซต'
- '๐ซต๐ป'
- '๐ซต๐ผ'
- '๐ซต๐ฝ'
- '๐ซต๐พ'
- '๐ซต๐ฟ'
- '๐ซถ'
- '๐ซถ๐ป'
- '๐ซถ๐ผ'
- '๐ซถ๐ฝ'
- '๐ซถ๐พ'
- '๐ซถ๐ฟ'
- '๐ค๐ป'
- '๐ค๐ผ'
- '๐ค๐ฝ'
- '๐ค๐พ'
- '๐ค๐ฟ'
- '๐ซฑ๐ปโ๐ซฒ๐ผ'
- '๐ซฑ๐ปโ๐ซฒ๐ฝ'
- '๐ซฑ๐ปโ๐ซฒ๐พ'
- '๐ซฑ๐ปโ๐ซฒ๐ฟ'
- '๐ซฑ๐ผโ๐ซฒ๐ป'
- '๐ซฑ๐ผโ๐ซฒ๐ฝ'
- '๐ซฑ๐ผโ๐ซฒ๐พ'
- '๐ซฑ๐ผโ๐ซฒ๐ฟ'
- '๐ซฑ๐ฝโ๐ซฒ๐ป'
- '๐ซฑ๐ฝโ๐ซฒ๐ผ'
- '๐ซฑ๐ฝโ๐ซฒ๐พ'
- '๐ซฑ๐ฝโ๐ซฒ๐ฟ'
- '๐ซฑ๐พโ๐ซฒ๐ป'
- '๐ซฑ๐พโ๐ซฒ๐ผ'
- '๐ซฑ๐พโ๐ซฒ๐ฝ'
- '๐ซฑ๐พโ๐ซฒ๐ฟ'
- '๐ซฑ๐ฟโ๐ซฒ๐ป'
- '๐ซฑ๐ฟโ๐ซฒ๐ผ'
- '๐ซฑ๐ฟโ๐ซฒ๐ฝ'
- '๐ซฑ๐ฟโ๐ซฒ๐พ'
- '๐ซฆ'
- '๐ซ
'
- '๐ซ
๐ป'
- '๐ซ
๐ผ'
- '๐ซ
๐ฝ'
- '๐ซ
๐พ'
- '๐ซ
๐ฟ'
- '๐ซ'
- '๐ซ๐ป'
- '๐ซ๐ผ'
- '๐ซ๐ฝ'
- '๐ซ๐พ'
- '๐ซ๐ฟ'
- '๐ซ'
- '๐ซ๐ป'
- '๐ซ๐ผ'
- '๐ซ๐ฝ'
- '๐ซ๐พ'
- '๐ซ๐ฟ'
- '๐ง'
- '๐ชธ'
- '๐ชท'
- '๐ชน'
- '๐ชบ'
- '๐ซ'
- '๐ซ'
- '๐ซ'
- '๐'
- '๐'
- '๐'
- '๐ชฌ'
- '๐ชฉ'
- '๐ชซ'
- '๐ฉผ'
- '๐ฉป'
- '๐ซง'
- '๐ชช'
- '๐ฐ'
- '๐ฎโ๐จ'
- '๐ตโ๐ซ'
- '๐ถโ๐ซ๏ธ'
- 'โค๏ธโ๐ฅ'
- 'โค๏ธโ๐ฉน'
- '๐งโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ฝโโ๏ธ'
- '๐ง๐พโโ๏ธ'
- '๐ง๐ฟโโ๏ธ'
- '๐งโโ๏ธ'
- '๐ง๐ปโโ๏ธ'
- '๐ง๐ผโโ๏ธ'
- '๐ง๐ฝโโ๏ธ'
- '๐ง๐พโโ๏ธ'
- '๐ง๐ฟโโ๏ธ'
- '๐๐ป'
- '๐๐ผ'
- '๐๐ฝ'
- '๐๐พ'
- '๐๐ฟ'
- '๐๐ป'
- '๐๐ผ'
- '๐๐ฝ'
- '๐๐พ'
- '๐๐ฟ'
- '๐จ๐ปโโค๏ธโ๐จ๐ป'
- '๐จ๐ปโโค๏ธโ๐จ๐ผ'
- '๐จ๐ปโโค๏ธโ๐จ๐ฝ'
- '๐จ๐ปโโค๏ธโ๐จ๐พ'
- '๐จ๐ปโโค๏ธโ๐จ๐ฟ'
- '๐จ๐ผโโค๏ธโ๐จ๐ป'
- '๐จ๐ผโโค๏ธโ๐จ๐ผ'
- '๐จ๐ผโโค๏ธโ๐จ๐ฝ'
- '๐จ๐ผโโค๏ธโ๐จ๐พ'
- '๐จ๐ผโโค๏ธโ๐จ๐ฟ'
- '๐จ๐ฝโโค๏ธโ๐จ๐ป'
- '๐จ๐ฝโโค๏ธโ๐จ๐ผ'
- '๐จ๐ฝโโค๏ธโ๐จ๐ฝ'
- '๐จ๐ฝโโค๏ธโ๐จ๐พ'
- '๐จ๐ฝโโค๏ธโ๐จ๐ฟ'
- '๐จ๐พโโค๏ธโ๐จ๐ป'
- '๐จ๐พโโค๏ธโ๐จ๐ผ'
- '๐จ๐พโโค๏ธโ๐จ๐ฝ'
- '๐จ๐พโโค๏ธโ๐จ๐พ'
- '๐จ๐พโโค๏ธโ๐จ๐ฟ'
- '๐จ๐ฟโโค๏ธโ๐จ๐ป'
- '๐จ๐ฟโโค๏ธโ๐จ๐ผ'
- '๐จ๐ฟโโค๏ธโ๐จ๐ฝ'
- '๐จ๐ฟโโค๏ธโ๐จ๐พ'
- '๐จ๐ฟโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐ปโโค๏ธโ๐จ๐ป'
- '๐ฉ๐ปโโค๏ธโ๐จ๐ผ'
- '๐ฉ๐ปโโค๏ธโ๐จ๐ฝ'
- '๐ฉ๐ปโโค๏ธโ๐จ๐พ'
- '๐ฉ๐ปโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐ปโโค๏ธโ๐ฉ๐ป'
- '๐ฉ๐ปโโค๏ธโ๐ฉ๐ผ'
- '๐ฉ๐ปโโค๏ธโ๐ฉ๐ฝ'
- '๐ฉ๐ปโโค๏ธโ๐ฉ๐พ'
- '๐ฉ๐ปโโค๏ธโ๐ฉ๐ฟ'
- '๐ฉ๐ผโโค๏ธโ๐จ๐ป'
- '๐ฉ๐ผโโค๏ธโ๐จ๐ผ'
- '๐ฉ๐ผโโค๏ธโ๐จ๐ฝ'
- '๐ฉ๐ผโโค๏ธโ๐จ๐พ'
- '๐ฉ๐ผโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐ผโโค๏ธโ๐ฉ๐ป'
- '๐ฉ๐ผโโค๏ธโ๐ฉ๐ผ'
- '๐ฉ๐ผโโค๏ธโ๐ฉ๐ฝ'
- '๐ฉ๐ผโโค๏ธโ๐ฉ๐พ'
- '๐ฉ๐ผโโค๏ธโ๐ฉ๐ฟ'
- '๐ฉ๐ฝโโค๏ธโ๐จ๐ป'
- '๐ฉ๐ฝโโค๏ธโ๐จ๐ผ'
- '๐ฉ๐ฝโโค๏ธโ๐จ๐ฝ'
- '๐ฉ๐ฝโโค๏ธโ๐จ๐พ'
- '๐ฉ๐ฝโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ป'
- '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ผ'
- '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฝ'
- '๐ฉ๐ฝโโค๏ธโ๐ฉ๐พ'
- '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฟ'
- '๐ฉ๐พโโค๏ธโ๐จ๐ป'
- '๐ฉ๐พโโค๏ธโ๐จ๐ผ'
- '๐ฉ๐พโโค๏ธโ๐จ๐ฝ'
- '๐ฉ๐พโโค๏ธโ๐จ๐พ'
- '๐ฉ๐พโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐พโโค๏ธโ๐ฉ๐ป'
- '๐ฉ๐พโโค๏ธโ๐ฉ๐ผ'
- '๐ฉ๐พโโค๏ธโ๐ฉ๐ฝ'
- '๐ฉ๐พโโค๏ธโ๐ฉ๐พ'
- '๐ฉ๐พโโค๏ธโ๐ฉ๐ฟ'
- '๐ฉ๐ฟโโค๏ธโ๐จ๐ป'
- '๐ฉ๐ฟโโค๏ธโ๐จ๐ผ'
- '๐ฉ๐ฟโโค๏ธโ๐จ๐ฝ'
- '๐ฉ๐ฟโโค๏ธโ๐จ๐พ'
- '๐ฉ๐ฟโโค๏ธโ๐จ๐ฟ'
- '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ป'
- '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ผ'
- '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฝ'
- '๐ฉ๐ฟโโค๏ธโ๐ฉ๐พ'
- '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฟ'
- '๐ง๐ปโโค๏ธโ๐ง๐ผ'
- '๐ง๐ปโโค๏ธโ๐ง๐ฝ'
- '๐ง๐ปโโค๏ธโ๐ง๐พ'
- '๐ง๐ปโโค๏ธโ๐ง๐ฟ'
- '๐ง๐ผโโค๏ธโ๐ง๐ป'
- '๐ง๐ผโโค๏ธโ๐ง๐ฝ'
- '๐ง๐ผโโค๏ธโ๐ง๐พ'
- '๐ง๐ผโโค๏ธโ๐ง๐ฟ'
- '๐ง๐ฝโโค๏ธโ๐ง๐ป'
- '๐ง๐ฝโโค๏ธโ๐ง๐ผ'
- '๐ง๐ฝโโค๏ธโ๐ง๐พ'
- '๐ง๐ฝโโค๏ธโ๐ง๐ฟ'
- '๐ง๐พโโค๏ธโ๐ง๐ป'
- '๐ง๐พโโค๏ธโ๐ง๐ผ'
- '๐ง๐พโโค๏ธโ๐ง๐ฝ'
- '๐ง๐พโโค๏ธโ๐ง๐ฟ'
- '๐ง๐ฟโโค๏ธโ๐ง๐ป'
- '๐ง๐ฟโโค๏ธโ๐ง๐ผ'
- '๐ง๐ฟโโค๏ธโ๐ง๐ฝ'
- '๐ง๐ฟโโค๏ธโ๐ง๐พ'
- '๐จ๐ปโโค๏ธโ๐โ๐จ๐ป'
- '๐จ๐ปโโค๏ธโ๐โ๐จ๐ผ'
- '๐จ๐ปโโค๏ธโ๐โ๐จ๐ฝ'
- '๐จ๐ปโโค๏ธโ๐โ๐จ๐พ'
- '๐จ๐ปโโค๏ธโ๐โ๐จ๐ฟ'
- '๐จ๐ผโโค๏ธโ๐โ๐จ๐ป'
- '๐จ๐ผโโค๏ธโ๐โ๐จ๐ผ'
- '๐จ๐ผโโค๏ธโ๐โ๐จ๐ฝ'
- '๐จ๐ผโโค๏ธโ๐โ๐จ๐พ'
- '๐จ๐ผโโค๏ธโ๐โ๐จ๐ฟ'
- '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ป'
- '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ผ'
- '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฝ'
- '๐จ๐ฝโโค๏ธโ๐โ๐จ๐พ'
- '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฟ'
- '๐จ๐พโโค๏ธโ๐โ๐จ๐ป'
- '๐จ๐พโโค๏ธโ๐โ๐จ๐ผ'
- '๐จ๐พโโค๏ธโ๐โ๐จ๐ฝ'
- '๐จ๐พโโค๏ธโ๐โ๐จ๐พ'
- '๐จ๐พโโค๏ธโ๐โ๐จ๐ฟ'
- '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ป'
- '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ผ'
- '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฝ'
- '๐จ๐ฟโโค๏ธโ๐โ๐จ๐พ'
- '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ป'
- '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ผ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฝ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐พ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ป'
- '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ผ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฝ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐พ'
- '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฟ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ป'
- '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ผ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฝ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐พ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ป'
- '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ผ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฝ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐พ'
- '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฟ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ป'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ผ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฝ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐พ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ป'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ผ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฝ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐พ'
- '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฟ'
- '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ป'
- '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ผ'
- '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฝ'
- '๐ฉ๐พโโค๏ธโ๐โ๐จ๐พ'
- '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ป'
- '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ผ'
- '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฝ'
- '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐พ'
- '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฟ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ป'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ผ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฝ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐พ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฟ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ป'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ผ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฝ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐พ'
- '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฟ'
- '๐ง๐ปโโค๏ธโ๐โ๐ง๐ผ'
- '๐ง๐ปโโค๏ธโ๐โ๐ง๐ฝ'
- '๐ง๐ปโโค๏ธโ๐โ๐ง๐พ'
- '๐ง๐ปโโค๏ธโ๐โ๐ง๐ฟ'
- '๐ง๐ผโโค๏ธโ๐โ๐ง๐ป'
- '๐ง๐ผโโค๏ธโ๐โ๐ง๐ฝ'
- '๐ง๐ผโโค๏ธโ๐โ๐ง๐พ'
- '๐ง๐ผโโค๏ธโ๐โ๐ง๐ฟ'
- '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ป'
- '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ผ'
- '๐ง๐ฝโโค๏ธโ๐โ๐ง๐พ'
- '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ฟ'
- '๐ง๐พโโค๏ธโ๐โ๐ง๐ป'
- '๐ง๐พโโค๏ธโ๐โ๐ง๐ผ'
- '๐ง๐พโโค๏ธโ๐โ๐ง๐ฝ'
- '๐ง๐พโโค๏ธโ๐โ๐ง๐ฟ'
- '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ป'
- '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ผ'
- '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ฝ'
- '๐ง๐ฟโโค๏ธโ๐โ๐ง๐พ'
condition: selection
falsepositives:
- Unknown
level: high
imProcessCreate
| where TargetProcessCommandLine contains "๐ธ" or TargetProcessCommandLine contains "๐น" or TargetProcessCommandLine contains "๐ถ" or TargetProcessCommandLine contains "๐ท" or TargetProcessCommandLine contains "๐ณ" or TargetProcessCommandLine contains "๐ฒ" or TargetProcessCommandLine contains "โช๏ธ" or TargetProcessCommandLine contains "โซ๏ธ" or TargetProcessCommandLine contains "โพ๏ธ" or TargetProcessCommandLine contains "โฝ๏ธ" or TargetProcessCommandLine contains "โผ๏ธ" or TargetProcessCommandLine contains "โป๏ธ" or TargetProcessCommandLine contains "๐ฅ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐จ" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐ฆ" or TargetProcessCommandLine contains "๐ช" or TargetProcessCommandLine contains "โฌ๏ธ" or TargetProcessCommandLine contains "โฌ๏ธ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฃ" or TargetProcessCommandLine contains "๐ข" or TargetProcessCommandLine contains "๐โ๐จ" or TargetProcessCommandLine contains "๐ฌ" or TargetProcessCommandLine contains "๐ญ" or TargetProcessCommandLine contains "๐ฏ" or TargetProcessCommandLine contains "โ ๏ธ" or TargetProcessCommandLine contains "โฃ๏ธ" or TargetProcessCommandLine contains "โฅ๏ธ" or TargetProcessCommandLine contains "โฆ๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ด" or TargetProcessCommandLine contains "๐๏ธ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ " or TargetProcessCommandLine contains "๐ก" or TargetProcessCommandLine contains "๐ข" or TargetProcessCommandLine contains "๐ฃ" or TargetProcessCommandLine contains "๐ค" or TargetProcessCommandLine contains "๐ฅ" or TargetProcessCommandLine contains "๐ฆ" or TargetProcessCommandLine contains "๐งโข" or TargetProcessCommandLine contains "โฃ" or TargetProcessCommandLine contains "โค" or TargetProcessCommandLine contains "โฅ" or TargetProcessCommandLine contains "โฆ" or TargetProcessCommandLine contains "โง" or TargetProcessCommandLine contains "โ
" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โฏ" or TargetProcessCommandLine contains "โก๏ธ" or TargetProcessCommandLine contains "โฉ" or TargetProcessCommandLine contains "โช" or TargetProcessCommandLine contains "โซ" or TargetProcessCommandLine contains "โฌ" or TargetProcessCommandLine contains "โญ" or TargetProcessCommandLine contains "โฎ" or TargetProcessCommandLine contains "โถ" or TargetProcessCommandLine contains "โท" or TargetProcessCommandLine contains "โต" or TargetProcessCommandLine contains "โธ" or TargetProcessCommandLine contains "โน" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โน" or TargetProcessCommandLine contains "โจ" or TargetProcessCommandLine contains "โพ" or TargetProcessCommandLine contains "โพ" or TargetProcessCommandLine contains "โข" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ ๏ธ" or TargetProcessCommandLine contains "โฃ๏ธ" or TargetProcessCommandLine contains "โฅ๏ธ" or TargetProcessCommandLine contains "โฆ๏ธ" or TargetProcessCommandLine contains "โค" or TargetProcessCommandLine contains "โง" or TargetProcessCommandLine contains "โก" or TargetProcessCommandLine contains "โข" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ
" or TargetProcessCommandLine contains "๐ " or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "โ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐
" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐๐ณ๏ธ" or TargetProcessCommandLine contains "๐ด" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฉ" or TargetProcessCommandLine contains "๐ณ๏ธโ๐" or TargetProcessCommandLine contains "๐ณ๏ธโโง๏ธ" or TargetProcessCommandLine contains "๐ดโโ ๏ธ" or TargetProcessCommandLine contains "๐ฆ๐ซ" or TargetProcessCommandLine contains "๐ฆ๐ฝ" or TargetProcessCommandLine contains "๐ฆ๐ฑ" or TargetProcessCommandLine contains "๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฆ๐ธ" or TargetProcessCommandLine contains "๐ฆ๐ฉ" or TargetProcessCommandLine contains "๐ฆ๐ด" or TargetProcessCommandLine contains "๐ฆ๐ฎ" or TargetProcessCommandLine contains "๐ฆ๐ถ" or TargetProcessCommandLine contains "๐ฆ๐ฌ" or TargetProcessCommandLine contains "๐ฆ๐ท" or TargetProcessCommandLine contains "๐ฆ๐ฒ" or TargetProcessCommandLine contains "๐ฆ๐ผ" or TargetProcessCommandLine contains "๐ฆ๐บ" or TargetProcessCommandLine contains "๐ฆ๐น" or TargetProcessCommandLine contains "๐ฆ๐ฟ" or TargetProcessCommandLine contains "๐ง๐ธ" or TargetProcessCommandLine contains "๐ง๐ญ" or TargetProcessCommandLine contains "๐ง๐ฉ" or TargetProcessCommandLine contains "๐ง๐ง" or TargetProcessCommandLine contains "๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ช" or TargetProcessCommandLine contains "๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ฏ" or TargetProcessCommandLine contains "๐ง๐ฒ" or TargetProcessCommandLine contains "๐ง๐น" or TargetProcessCommandLine contains "๐ง๐ด" or TargetProcessCommandLine contains "๐ง๐ฆ" or TargetProcessCommandLine contains "๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ท" or TargetProcessCommandLine contains "๐ฎ๐ด" or TargetProcessCommandLine contains "๐ป๐ฌ" or TargetProcessCommandLine contains "๐ง๐ณ" or TargetProcessCommandLine contains "๐ง๐ฌ" or TargetProcessCommandLine contains "๐ง๐ซ" or TargetProcessCommandLine contains "๐ง๐ฎ" or TargetProcessCommandLine contains "๐ฐ๐ญ" or TargetProcessCommandLine contains "๐จ๐ฒ" or TargetProcessCommandLine contains "๐จ๐ฆ" or TargetProcessCommandLine contains "๐ฎ๐จ" or TargetProcessCommandLine contains "๐จ๐ป" or TargetProcessCommandLine contains "๐ง๐ถ" or TargetProcessCommandLine contains "๐ฐ๐พ" or TargetProcessCommandLine contains "๐จ๐ซ" or TargetProcessCommandLine contains "๐น๐ฉ" or TargetProcessCommandLine contains "๐จ๐ฑ" or TargetProcessCommandLine contains "๐จ๐ณ" or TargetProcessCommandLine contains "๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐จ" or TargetProcessCommandLine contains "๐จ๐ด" or TargetProcessCommandLine contains "๐ฐ๐ฒ" or TargetProcessCommandLine contains "๐จ๐ฌ" or TargetProcessCommandLine contains "๐จ๐ฉ" or TargetProcessCommandLine contains "๐จ๐ฐ" or TargetProcessCommandLine contains "๐จ๐ท" or TargetProcessCommandLine contains "๐จ๐ฎ" or TargetProcessCommandLine contains "๐ญ๐ท" or TargetProcessCommandLine contains "๐จ๐บ" or TargetProcessCommandLine contains "๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฐ" or TargetProcessCommandLine contains "๐ฉ๐ฏ" or TargetProcessCommandLine contains "๐ฉ๐ฒ" or TargetProcessCommandLine contains "๐ฉ๐ด" or TargetProcessCommandLine contains "๐ช๐จ" or TargetProcessCommandLine contains "๐ช๐ฌ" or TargetProcessCommandLine contains "๐ธ๐ป" or TargetProcessCommandLine contains "๐ฌ๐ถ" or TargetProcessCommandLine contains "๐ช๐ท" or TargetProcessCommandLine contains "๐ช๐ช" or TargetProcessCommandLine contains "๐ช๐น" or TargetProcessCommandLine contains "๐ช๐บ" or TargetProcessCommandLine contains "๐ซ๐ฐ" or TargetProcessCommandLine contains "๐ซ๐ด" or TargetProcessCommandLine contains "๐ซ๐ฏ" or TargetProcessCommandLine contains "๐ซ๐ฎ" or TargetProcessCommandLine contains "๐ซ๐ท" or TargetProcessCommandLine contains "๐ฌ๐ซ" or TargetProcessCommandLine contains "๐ต๐ซ" or TargetProcessCommandLine contains "๐น๐ซ" or TargetProcessCommandLine contains "๐ฌ๐ฆ" or TargetProcessCommandLine contains "๐ฌ๐ฒ" or TargetProcessCommandLine contains "๐ฌ๐ช" or TargetProcessCommandLine contains "๐ฉ๐ช" or TargetProcessCommandLine contains "๐ฌ๐ญ" or TargetProcessCommandLine contains "๐ฌ๐ฎ" or TargetProcessCommandLine contains "๐ฌ๐ท" or TargetProcessCommandLine contains "๐ฌ๐ฑ" or TargetProcessCommandLine contains "๐ฌ๐ฉ" or TargetProcessCommandLine contains "๐ฌ๐ต" or TargetProcessCommandLine contains "๐ฌ๐บ" or TargetProcessCommandLine contains "๐ฌ๐น" or TargetProcessCommandLine contains "๐ฌ๐ฌ" or TargetProcessCommandLine contains "๐ฌ๐ณ" or TargetProcessCommandLine contains "๐ฌ๐ผ" or TargetProcessCommandLine contains "๐ฌ๐พ" or TargetProcessCommandLine contains "๐ญ๐น" or TargetProcessCommandLine contains "๐ญ๐ณ" or TargetProcessCommandLine contains "๐ญ๐ฐ" or TargetProcessCommandLine contains "๐ญ๐บ" or TargetProcessCommandLine contains "๐ฎ๐ธ" or TargetProcessCommandLine contains "๐ฎ๐ณ" or TargetProcessCommandLine contains "๐ฎ๐ฉ" or TargetProcessCommandLine contains "๐ฎ๐ท" or TargetProcessCommandLine contains "๐ฎ๐ถ" or TargetProcessCommandLine contains "๐ฎ๐ช" or TargetProcessCommandLine contains "๐ฎ๐ฒ" or TargetProcessCommandLine contains "๐ฎ๐ฑ" or TargetProcessCommandLine contains "๐ฎ๐น" or TargetProcessCommandLine contains "๐ฏ๐ฒ" or TargetProcessCommandLine contains "๐ฏ๐ต" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ฏ๐ช" or TargetProcessCommandLine contains "๐ฏ๐ด" or TargetProcessCommandLine contains "๐ฐ๐ฟ" or TargetProcessCommandLine contains "๐ฐ๐ช" or TargetProcessCommandLine contains "๐ฐ๐ฎ" or TargetProcessCommandLine contains "๐ฝ๐ฐ" or TargetProcessCommandLine contains "๐ฐ๐ผ" or TargetProcessCommandLine contains "๐ฐ๐ฌ" or TargetProcessCommandLine contains "๐ฑ๐ฆ" or TargetProcessCommandLine contains "๐ฑ๐ป" or TargetProcessCommandLine contains "๐ฑ๐ง" or TargetProcessCommandLine contains "๐ฑ๐ธ" or TargetProcessCommandLine contains "๐ฑ๐ท" or TargetProcessCommandLine contains "๐ฑ๐พ" or TargetProcessCommandLine contains "๐ฑ๐ฎ" or TargetProcessCommandLine contains "๐ฑ๐น" or TargetProcessCommandLine contains "๐ฑ๐บ" or TargetProcessCommandLine contains "๐ฒ๐ด" or TargetProcessCommandLine contains "๐ฒ๐ฐ" or TargetProcessCommandLine contains "๐ฒ๐ฌ" or TargetProcessCommandLine contains "๐ฒ๐ผ" or TargetProcessCommandLine contains "๐ฒ๐พ" or TargetProcessCommandLine contains "๐ฒ๐ป" or TargetProcessCommandLine contains "๐ฒ๐ฑ" or TargetProcessCommandLine contains "๐ฒ๐น" or TargetProcessCommandLine contains "๐ฒ๐ญ" or TargetProcessCommandLine contains "๐ฒ๐ถ" or TargetProcessCommandLine contains "๐ฒ๐ท" or TargetProcessCommandLine contains "๐ฒ๐บ" or TargetProcessCommandLine contains "๐พ๐น" or TargetProcessCommandLine contains "๐ฒ๐ฝ" or TargetProcessCommandLine contains "๐ซ๐ฒ" or TargetProcessCommandLine contains "๐ฒ๐ฉ" or TargetProcessCommandLine contains "๐ฒ๐จ" or TargetProcessCommandLine contains "๐ฒ๐ณ" or TargetProcessCommandLine contains "๐ฒ๐ช" or TargetProcessCommandLine contains "๐ฒ๐ธ" or TargetProcessCommandLine contains "๐ฒ๐ฆ" or TargetProcessCommandLine contains "๐ฒ๐ฟ" or TargetProcessCommandLine contains "๐ฒ๐ฒ" or TargetProcessCommandLine contains "๐ณ๐ฆ" or TargetProcessCommandLine contains "๐ณ๐ท" or TargetProcessCommandLine contains "๐ณ๐ต" or TargetProcessCommandLine contains "๐ณ๐ฑ" or TargetProcessCommandLine contains "๐ณ๐จ" or TargetProcessCommandLine contains "๐ณ๐ฟ" or TargetProcessCommandLine contains "๐ณ๐ฎ" or TargetProcessCommandLine contains "๐ณ๐ช" or TargetProcessCommandLine contains "๐ณ๐ฌ" or TargetProcessCommandLine contains "๐ณ๐บ" or TargetProcessCommandLine contains "๐ณ๐ซ" or TargetProcessCommandLine contains "๐ฐ๐ต" or TargetProcessCommandLine contains "๐ฒ๐ต" or TargetProcessCommandLine contains "๐ณ๐ด" or TargetProcessCommandLine contains "๐ด๐ฒ" or TargetProcessCommandLine contains "๐ต๐ฐ" or TargetProcessCommandLine contains "๐ต๐ผ" or TargetProcessCommandLine contains "๐ต๐ธ" or TargetProcessCommandLine contains "๐ต๐ฆ" or TargetProcessCommandLine contains "๐ต๐ฌ" or TargetProcessCommandLine contains "๐ต๐พ" or TargetProcessCommandLine contains "๐ต๐ช" or TargetProcessCommandLine contains "๐ต๐ญ" or TargetProcessCommandLine contains "๐ต๐ณ" or TargetProcessCommandLine contains "๐ต๐ฑ" or TargetProcessCommandLine contains "๐ต๐น" or TargetProcessCommandLine contains "๐ต๐ท" or TargetProcessCommandLine contains "๐ถ๐ฆ" or TargetProcessCommandLine contains "๐ท๐ช" or TargetProcessCommandLine contains "๐ท๐ด" or TargetProcessCommandLine contains "๐ท๐บ" or TargetProcessCommandLine contains "๐ท๐ผ" or TargetProcessCommandLine contains "๐ผ๐ธ" or TargetProcessCommandLine contains "๐ธ๐ฒ" or TargetProcessCommandLine contains "๐ธ๐ฆ" or TargetProcessCommandLine contains "๐ธ๐ณ" or TargetProcessCommandLine contains "๐ท๐ธ" or TargetProcessCommandLine contains "๐ธ๐จ" or TargetProcessCommandLine contains "๐ธ๐ฑ" or TargetProcessCommandLine contains "๐ธ๐ฌ" or TargetProcessCommandLine contains "๐ธ๐ฝ" or TargetProcessCommandLine contains "๐ธ๐ฐ" or TargetProcessCommandLine contains "๐ธ๐ฎ" or TargetProcessCommandLine contains "๐ฌ๐ธ" or TargetProcessCommandLine contains "๐ธ๐ง" or TargetProcessCommandLine contains "๐ธ๐ด" or TargetProcessCommandLine contains "๐ฟ๐ฆ" or TargetProcessCommandLine contains "๐ฐ๐ท" or TargetProcessCommandLine contains "๐ธ๐ธ" or TargetProcessCommandLine contains "๐ช๐ธ" or TargetProcessCommandLine contains "๐ฑ๐ฐ" or TargetProcessCommandLine contains "๐ง๐ฑ" or TargetProcessCommandLine contains "๐ธ๐ญ" or TargetProcessCommandLine contains "๐ฐ๐ณ" or TargetProcessCommandLine contains "๐ฑ๐จ" or TargetProcessCommandLine contains "๐ต๐ฒ" or TargetProcessCommandLine contains "๐ป๐จ" or TargetProcessCommandLine contains "๐ธ๐ฉ" or TargetProcessCommandLine contains "๐ธ๐ท" or TargetProcessCommandLine contains "๐ธ๐ฟ" or TargetProcessCommandLine contains "๐ธ๐ช" or TargetProcessCommandLine contains "๐จ๐ญ" or TargetProcessCommandLine contains "๐ธ๐พ" or TargetProcessCommandLine contains "๐น๐ผ" or TargetProcessCommandLine contains "๐น๐ฏ" or TargetProcessCommandLine contains "๐น๐ฟ" or TargetProcessCommandLine contains "๐น๐ญ" or TargetProcessCommandLine contains "๐น๐ฑ" or TargetProcessCommandLine contains "๐น๐ฌ" or TargetProcessCommandLine contains "๐น๐ฐ" or TargetProcessCommandLine contains "๐น๐ด" or TargetProcessCommandLine contains "๐น๐น" or TargetProcessCommandLine contains "๐น๐ณ" or TargetProcessCommandLine contains "๐น๐ท" or TargetProcessCommandLine contains "๐น๐ฒ" or TargetProcessCommandLine contains "๐น๐จ" or TargetProcessCommandLine contains "๐น๐ป" or TargetProcessCommandLine contains "๐ป๐ฎ" or TargetProcessCommandLine contains "๐บ๐ฌ" or TargetProcessCommandLine contains "๐บ๐ฆ" or TargetProcessCommandLine contains "๐ฆ๐ช" or TargetProcessCommandLine contains "๐ฌ๐ง" or TargetProcessCommandLine contains "๐ด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ" or TargetProcessCommandLine contains "๐ด๓ ง๓ ข๓ ณ๓ ฃ๓ ด๓ ฟ" or TargetProcessCommandLine contains "๐ด๓ ง๓ ข๓ ท๓ ฌ๓ ณ๓ ฟ" or TargetProcessCommandLine contains "๐บ๐ณ" or TargetProcessCommandLine contains "๐บ๐ธ" or TargetProcessCommandLine contains "๐บ๐พ" or TargetProcessCommandLine contains "๐บ๐ฟ" or TargetProcessCommandLine contains "๐ป๐บ" or TargetProcessCommandLine contains "๐ป๐ฆ" or TargetProcessCommandLine contains "๐ป๐ช" or TargetProcessCommandLine contains "๐ป๐ณ" or TargetProcessCommandLine contains "๐ผ๐ซ" or TargetProcessCommandLine contains "๐ช๐ญ" or TargetProcessCommandLine contains "๐พ๐ช" or TargetProcessCommandLine contains "๐ฟ๐ฒ" or TargetProcessCommandLine contains "๐ฟ๐ผ๐ซ " or TargetProcessCommandLine contains "๐ซข" or TargetProcessCommandLine contains "๐ซฃ" or TargetProcessCommandLine contains "๐ซก" or TargetProcessCommandLine contains "๐ซฅ" or TargetProcessCommandLine contains "๐ซค" or TargetProcessCommandLine contains "๐ฅน" or TargetProcessCommandLine contains "๐ซฑ" or TargetProcessCommandLine contains "๐ซฑ๐ป" or TargetProcessCommandLine contains "๐ซฑ๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐ฝ" or TargetProcessCommandLine contains "๐ซฑ๐พ" or TargetProcessCommandLine contains "๐ซฑ๐ฟ" or TargetProcessCommandLine contains "๐ซฒ" or TargetProcessCommandLine contains "๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซฒ๐ฝ" or TargetProcessCommandLine contains "๐ซฒ๐พ" or TargetProcessCommandLine contains "๐ซฒ๐ฟ" or TargetProcessCommandLine contains "๐ซณ" or TargetProcessCommandLine contains "๐ซณ๐ป" or TargetProcessCommandLine contains "๐ซณ๐ผ" or TargetProcessCommandLine contains "๐ซณ๐ฝ" or TargetProcessCommandLine contains "๐ซณ๐พ" or TargetProcessCommandLine contains "๐ซณ๐ฟ" or TargetProcessCommandLine contains "๐ซด" or TargetProcessCommandLine contains "๐ซด๐ป" or TargetProcessCommandLine contains "๐ซด๐ผ" or TargetProcessCommandLine contains "๐ซด๐ฝ" or TargetProcessCommandLine contains "๐ซด๐พ" or TargetProcessCommandLine contains "๐ซด๐ฟ" or TargetProcessCommandLine contains "๐ซฐ" or TargetProcessCommandLine contains "๐ซฐ๐ป" or TargetProcessCommandLine contains "๐ซฐ๐ผ" or TargetProcessCommandLine contains "๐ซฐ๐ฝ" or TargetProcessCommandLine contains "๐ซฐ๐พ" or TargetProcessCommandLine contains "๐ซฐ๐ฟ" or TargetProcessCommandLine contains "๐ซต" or TargetProcessCommandLine contains "๐ซต๐ป" or TargetProcessCommandLine contains "๐ซต๐ผ" or TargetProcessCommandLine contains "๐ซต๐ฝ" or TargetProcessCommandLine contains "๐ซต๐พ" or TargetProcessCommandLine contains "๐ซต๐ฟ" or TargetProcessCommandLine contains "๐ซถ" or TargetProcessCommandLine contains "๐ซถ๐ป" or TargetProcessCommandLine contains "๐ซถ๐ผ" or TargetProcessCommandLine contains "๐ซถ๐ฝ" or TargetProcessCommandLine contains "๐ซถ๐พ" or TargetProcessCommandLine contains "๐ซถ๐ฟ" or TargetProcessCommandLine contains "๐ค๐ป" or TargetProcessCommandLine contains "๐ค๐ผ" or TargetProcessCommandLine contains "๐ค๐ฝ" or TargetProcessCommandLine contains "๐ค๐พ" or TargetProcessCommandLine contains "๐ค๐ฟ" or TargetProcessCommandLine contains "๐ซฑ๐ปโ๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐ปโ๐ซฒ๐ฝ" or TargetProcessCommandLine contains "๐ซฑ๐ปโ๐ซฒ๐พ" or TargetProcessCommandLine contains "๐ซฑ๐ปโ๐ซฒ๐ฟ" or TargetProcessCommandLine contains "๐ซฑ๐ผโ๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซฑ๐ผโ๐ซฒ๐ฝ" or TargetProcessCommandLine contains "๐ซฑ๐ผโ๐ซฒ๐พ" or TargetProcessCommandLine contains "๐ซฑ๐ผโ๐ซฒ๐ฟ" or TargetProcessCommandLine contains "๐ซฑ๐ฝโ๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซฑ๐ฝโ๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐ฝโ๐ซฒ๐พ" or TargetProcessCommandLine contains "๐ซฑ๐ฝโ๐ซฒ๐ฟ" or TargetProcessCommandLine contains "๐ซฑ๐พโ๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซฑ๐พโ๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐พโ๐ซฒ๐ฝ" or TargetProcessCommandLine contains "๐ซฑ๐พโ๐ซฒ๐ฟ" or TargetProcessCommandLine contains "๐ซฑ๐ฟโ๐ซฒ๐ป" or TargetProcessCommandLine contains "๐ซฑ๐ฟโ๐ซฒ๐ผ" or TargetProcessCommandLine contains "๐ซฑ๐ฟโ๐ซฒ๐ฝ" or TargetProcessCommandLine contains "๐ซฑ๐ฟโ๐ซฒ๐พ" or TargetProcessCommandLine contains "๐ซฆ" or TargetProcessCommandLine contains "๐ซ
" or TargetProcessCommandLine contains "๐ซ
๐ป" or TargetProcessCommandLine contains "๐ซ
๐ผ" or TargetProcessCommandLine contains "๐ซ
๐ฝ" or TargetProcessCommandLine contains "๐ซ
๐พ" or TargetProcessCommandLine contains "๐ซ
๐ฟ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ๐ป" or TargetProcessCommandLine contains "๐ซ๐ผ" or TargetProcessCommandLine contains "๐ซ๐ฝ" or TargetProcessCommandLine contains "๐ซ๐พ" or TargetProcessCommandLine contains "๐ซ๐ฟ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ๐ป" or TargetProcessCommandLine contains "๐ซ๐ผ" or TargetProcessCommandLine contains "๐ซ๐ฝ" or TargetProcessCommandLine contains "๐ซ๐พ" or TargetProcessCommandLine contains "๐ซ๐ฟ" or TargetProcessCommandLine contains "๐ง" or TargetProcessCommandLine contains "๐ชธ" or TargetProcessCommandLine contains "๐ชท" or TargetProcessCommandLine contains "๐ชน" or TargetProcessCommandLine contains "๐ชบ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐ซ" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐" or TargetProcessCommandLine contains "๐ชฌ" or TargetProcessCommandLine contains "๐ชฉ" or TargetProcessCommandLine contains "๐ชซ" or TargetProcessCommandLine contains "๐ฉผ" or TargetProcessCommandLine contains "๐ฉป" or TargetProcessCommandLine contains "๐ซง" or TargetProcessCommandLine contains "๐ชช" or TargetProcessCommandLine contains "๐ฐ" or TargetProcessCommandLine contains "๐ฎโ๐จ" or TargetProcessCommandLine contains "๐ตโ๐ซ" or TargetProcessCommandLine contains "๐ถโ๐ซ๏ธ" or TargetProcessCommandLine contains "โค๏ธโ๐ฅ" or TargetProcessCommandLine contains "โค๏ธโ๐ฉน" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ฝโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐พโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ฟโโ๏ธ" or TargetProcessCommandLine contains "๐งโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ปโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ผโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ฝโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐พโโ๏ธ" or TargetProcessCommandLine contains "๐ง๐ฟโโ๏ธ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ฝ" or TargetProcessCommandLine contains "๐๐พ" or TargetProcessCommandLine contains "๐๐ฟ" or TargetProcessCommandLine contains "๐๐ป" or TargetProcessCommandLine contains "๐๐ผ" or TargetProcessCommandLine contains "๐๐ฝ" or TargetProcessCommandLine contains "๐๐พ" or TargetProcessCommandLine contains "๐๐ฟ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐ง๐พ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ปโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ผโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐พโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฟ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ป" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ผ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฝ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐พ" or TargetProcessCommandLine contains "๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฟ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐โ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐โ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐โ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ปโโค๏ธโ๐โ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐โ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐โ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐โ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ผโโค๏ธโ๐โ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐โ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐โ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐โ๐ง๐พ" or TargetProcessCommandLine contains "๐ง๐ฝโโค๏ธโ๐โ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐โ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐โ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐โ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐พโโค๏ธโ๐โ๐ง๐ฟ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐โ๐ง๐ป" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐โ๐ง๐ผ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐โ๐ง๐ฝ" or TargetProcessCommandLine contains "๐ง๐ฟโโค๏ธโ๐โ๐ง๐พ"
| Sentinel Table | Notes |
|---|---|
imProcessCreate | Ensure this data connector is enabled |