.. |
powershell_accessing_win_api.yml
|
Update powershell_accessing_win_api.yml
|
2020-10-07 14:47:29 +03:00 |
powershell_alternate_powershell_hosts.yml
|
fixed various spelling errors all over rules and source code
|
2021-02-24 14:43:13 +00:00 |
powershell_bad_opsec_artifacts.yml
|
Some minor formatting updates;
|
2020-10-14 16:55:52 -04:00 |
powershell_CL_Invocation_LOLScript_v2.yml
|
Update powershell_CL_Invocation_LOLScript_v2.yml
|
2020-10-28 19:30:21 +03:00 |
powershell_CL_Invocation_LOLScript.yml
|
Update powershell_CL_Invocation_LOLScript.yml
|
2020-10-28 19:25:43 +03:00 |
powershell_CL_Mutexverifiers_LOLScript_v2.yml
|
Update powershell_CL_Mutexverifiers_LOLScript_v2.yml
|
2020-10-28 19:32:18 +03:00 |
powershell_CL_Mutexverifiers_LOLScript.yml
|
Splitting into two rules
|
2020-10-28 19:13:29 +03:00 |
powershell_clear_powershell_history.yml
|
Update powershell_clear_powershell_history.yml
|
2020-11-28 09:26:18 +01:00 |
powershell_cmdline_reversed_strings.yml
|
Update powershell_cmdline_reversed_strings.yml
|
2020-10-11 23:40:12 +03:00 |
powershell_cmdline_special_characters.yml
|
fix: missing new line placeholder escape
|
2021-04-09 16:45:07 +02:00 |
powershell_cmdline_specific_comb_methods.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_code_injection.yml
|
Clean-up service: sysmon as it will be replaced by filling the category
|
2021-04-15 02:02:25 +02:00 |
powershell_create_local_user.yml
|
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
|
2020-08-24 23:31:26 +00:00 |
powershell_data_compressed.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_decompress_commands.yml
|
Fixes&improvements
|
2021-04-08 01:06:40 +02:00 |
powershell_dnscat_execution.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_downgrade_attack.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_exe_calling_ps.yml
|
Update powershell_exe_calling_ps.yml
|
2020-10-15 17:09:47 -03:00 |
powershell_get_clipboard.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
powershell_icmp_exfiltration.yml
|
remove redundant reference
|
2020-10-11 23:35:17 +02:00 |
powershell_invoke_obfuscation_clip+.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_obfuscated_iex.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_invoke_obfuscation_stdin+.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_var+.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_compress.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_rundll.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_stdin.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_use_clip.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_use_mhsta.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_use_rundll32.yml
|
Fixes and improvements
|
2021-04-03 00:08:55 +02:00 |
powershell_invoke_obfuscation_via_var++.yml
|
fix: rules causing too many false positives
|
2021-04-09 15:55:14 +02:00 |
powershell_malicious_commandlets.yml
|
Update powershell_malicious_commandlets.yml
|
2020-10-15 20:59:27 -03:00 |
powershell_malicious_keywords.yml
|
Update powershell_malicious_keywords.yml
|
2020-10-15 17:12:08 -03:00 |
powershell_nishang_malicious_commandlets.yml
|
docs: changed modification date
|
2021-04-23 14:55:04 +02:00 |
powershell_ntfs_ads_access.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_prompt_credentials.yml
|
Update powershell_prompt_credentials.yml
|
2020-10-15 17:13:16 -03:00 |
powershell_psattack.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_remote_powershell_session.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_shellcode_b64.yml
|
Fixes
|
2021-04-03 23:21:13 +02:00 |
powershell_suspicious_download.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_suspicious_export_pfxcertificate.yml
|
fix: fixed rule title
|
2021-04-23 09:51:31 +02:00 |
powershell_suspicious_getprocess_lsass.yml
|
rule: get-process lsass
|
2021-04-23 16:44:53 +02:00 |
powershell_suspicious_invocation_generic.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_suspicious_invocation_specific.yml
|
Improve Logic
|
2020-11-20 01:22:20 -03:00 |
powershell_suspicious_keywords.yml
|
fix: search for keywords within message
|
2021-02-26 09:42:12 +01:00 |
powershell_suspicious_mounted_share_deletion.yml
|
Update powershell_suspicious_mounted_share_deletion.yml
|
2020-10-07 17:54:48 +11:00 |
powershell_suspicious_profile_create.yml
|
- Cleaned up some more rules where 'service: sysmon' was combined with category
|
2020-10-02 10:45:29 +02:00 |
powershell_winlogon_helper_dll.yml
|
Update powershell_winlogon_helper_dll.yml
|
2020-12-01 02:23:02 +01:00 |
powershell_wmimplant.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
powershell_wsman_com_provider_no_powershell.yml
|
Fixes&improvements
|
2021-04-08 01:06:40 +02:00 |
powershell_xor_commandline.yml
|
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
|
2020-08-25 23:51:22 +00:00 |
win_powershell_web_request.yml
|
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
|
2020-08-24 23:31:26 +00:00 |