mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-06 17:35:19 +00:00
LiquidSnake named pipe
This commit is contained in:
parent
f102b2d9a1
commit
affc929c3b
@ -34,6 +34,7 @@ detection:
|
||||
- '\Posh*' #PoshC2 default
|
||||
- '\jaccdpqnvbrrxlaf' #PoshC2 default
|
||||
- '\csexecsvc' #CSEXEC default
|
||||
- '\6e7645c4-32c5-4fe3-aabf-e94c2f4370e7' # LiquidSnake https://github.com/RiccardoAncarani/LiquidSnake
|
||||
condition: selection
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
|
Loading…
Reference in New Issue
Block a user