1C:Enterprise loads malicious external processing Obrabotka_bez_svedeniy.epf
Detects the execution of 1C:Enterprise business automation software processes (1cv8.exe, 1cv8c.exe, rphost.exe) using specific suspicious external processing files (epf) such as 'Obrabotka_bez_svedeniy.epf' or 'ExternalProcessing1'. This includes detection of the file creation event to identify potential persistence or execution of malicious automation scripts within the 1C environment.
Microsoft Sentinel (KQL)

