Vulnerability/Assessment File Creation Detection
Detects the creation of files containing keywords such as 'vulnerability', 'assessment', or 'scan'. This rule aims to identify activities related to vulnerability scanning or security assessments being performed on a system, potentially indicating reconnaissance or unauthorized activity. The events are summarized by the initiating process account name and time to help identify the source of these activities.
Microsoft Sentinel (KQL)

