SigmaHQ/rules/windows/powershell
2020-11-28 09:26:18 +01:00
..
powershell_alternate_powershell_hosts.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_clear_powershell_history.yml Update powershell_clear_powershell_history.yml 2020-11-28 09:26:18 +01:00
powershell_create_local_user.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_data_compressed.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_dnscat_execution.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_downgrade_attack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_exe_calling_ps.yml Update powershell_exe_calling_ps.yml 2020-10-15 17:09:47 -03:00
powershell_invoke_obfuscation_obfuscated_iex.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_malicious_commandlets.yml Update powershell_malicious_commandlets.yml 2020-10-15 20:59:27 -03:00
powershell_malicious_keywords.yml Update powershell_malicious_keywords.yml 2020-10-15 17:12:08 -03:00
powershell_nishang_malicious_commandlets.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_ntfs_ads_access.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_prompt_credentials.yml Update powershell_prompt_credentials.yml 2020-10-15 17:13:16 -03:00
powershell_psattack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_remote_powershell_session.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_shellcode_b64.yml Update powershell_shellcode_b64.yml 2020-10-15 17:14:01 -03:00
powershell_suspicious_download.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_generic.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_specific.yml Improve Logic 2020-11-20 01:22:20 -03:00
powershell_suspicious_keywords.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_profile_create.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_winlogon_helper_dll.yml Update powershell_winlogon_helper_dll.yml 2020-10-15 17:15:23 -03:00
powershell_wmimplant.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_xor_commandline.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
win_powershell_web_request.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00