mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Add keyword WinRM to remote powershell process rule
This commit is contained in:
parent
b46f65965d
commit
93241e7fc6
@ -1,4 +1,4 @@
|
||||
title: Remote PowerShell Session (WinRM)
|
||||
title: Remote PowerShell Session Host Process (WinRM)
|
||||
id: 734f8d9b-42b8-41b2-bcf5-abaf49d5a3c8
|
||||
description: Detects remote PowerShell sections by monitoring for wsmprovhost (WinRM host process) as a parent or child process (sign of an active ps remote session)
|
||||
status: experimental
|
||||
|
Loading…
Reference in New Issue
Block a user