Trickbot Reconnaissance Activity Detected
Detects host-based reconnaissance activity patterns indicative of Trickbot malware. The rule monitors for a high frequency (>= 4 unique commands within a 30-minute window) of diagnostic commands ('tasklist', 'systeminfo', 'ipconfig', 'net') executed by cmd.exe or powershell.exe, which is a common behavior pattern for adversary discovery processes.
Microsoft Sentinel (KQL)

