mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
Add modified field in WinRM rule
This commit is contained in:
parent
93241e7fc6
commit
d8ec5fa6af
@ -3,6 +3,7 @@ id: 13acf386-b8c6-4fe0-9a6e-c4756b974698
|
||||
description: Detects basic PowerShell Remoting (WinRM) by monitoring for network inbound connections to ports 5985 OR 5986
|
||||
status: experimental
|
||||
date: 2019/09/12
|
||||
modified: 2021/05/21
|
||||
author: Roberto Rodriguez @Cyb3rWard0g
|
||||
references:
|
||||
- https://github.com/Cyb3rWard0g/ThreatHunter-Playbook/tree/master/playbooks/windows/02_execution/T1086_powershell/powershell_remote_session.md
|
||||
|
Loading…
Reference in New Issue
Block a user