.. |
powershell_alternate_powershell_hosts.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_clear_powershell_history.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_create_local_user.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_data_compressed.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_dnscat_execution.yml
|
Rule fixes
|
2020-02-20 23:00:16 +01:00 |
powershell_downgrade_attack.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_exe_calling_ps.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_invoke_obfuscation_obfuscated_iex.yml
|
Rule fixes
|
2020-02-20 23:00:16 +01:00 |
powershell_malicious_commandlets.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_malicious_keywords.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_nishang_malicious_commandlets.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_ntfs_ads_access.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_prompt_credentials.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_psattack.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_remote_powershell_session.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_shellcode_b64.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_suspicious_download.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_suspicious_invocation_generic.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_suspicious_invocation_specific.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_suspicious_keywords.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_suspicious_profile_create.yml
|
Update powershell_suspicious_profile_create.yml
|
2020-04-03 09:36:17 +02:00 |
powershell_winlogon_helper_dll.yml
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
powershell_wmimplant.yml
|
Disabled keywords that could cause FPs
|
2020-03-30 08:53:52 +02:00 |