mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
30fc4bd030
New rule to detect -bxor usage in a powershell commandline. |
||
---|---|---|
.. | ||
powershell_downgrade_attack.yml | ||
powershell_exe_calling_ps.yml | ||
powershell_malicious_commandlets.yml | ||
powershell_malicious_keywords.yml | ||
powershell_NTFS_Alternate_Data_Streams | ||
powershell_prompt_credentials.yml | ||
powershell_psattack.yml | ||
powershell_suspicious_download.yml | ||
powershell_suspicious_invocation_generic.yml | ||
powershell_suspicious_invocation_specific.yml | ||
powershell_xor_commandline.yml |