Suspicious GlobalProtect Executable File Detected
This rule detects the presence or execution of a file named 'GlobalProtect.exe' within the Palo Alto GlobalProtect directory. It focuses on identifying potentially masqueraded or unauthorized binaries by monitoring file events and associated process execution. This pattern is commonly used by attackers to disguise malicious files as legitimate security software to evade detection.
Microsoft Sentinel (KQL)

