mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
Fixed rule
This commit is contained in:
parent
a2da73053d
commit
ff98991c80
@ -1,3 +1,4 @@
|
||||
action: global
|
||||
title: Suspicious Encoded PowerShell Command Line
|
||||
description: Detects suspicious powershell process which includes bxor command, alternatvide obfuscation method to b64 encoded commands.
|
||||
status: experimental
|
||||
|
Loading…
Reference in New Issue
Block a user