SigmaHQ/rules/windows/powershell
2020-04-14 13:37:10 +02:00
..
powershell_alternate_powershell_hosts.yml docs: more false positive conditions 2020-02-25 11:13:58 +01:00
powershell_clear_powershell_history.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
powershell_create_local_user.yml Adjusted level 2020-04-14 13:37:10 +02:00
powershell_data_compressed.yml Data Compressed duplciate titles 2019-12-09 16:24:10 +00:00
powershell_dnscat_execution.yml Rule fixes 2020-02-20 23:00:16 +01:00
powershell_downgrade_attack.yml Restructure new improvement to process_creation folder. 2020-03-20 23:29:32 +01:00
powershell_exe_calling_ps.yml fix: fixed casing and long rule titles 2020-01-30 17:26:09 +01:00
powershell_invoke_obfuscation_obfuscated_iex.yml Rule fixes 2020-02-20 23:00:16 +01:00
powershell_malicious_commandlets.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_malicious_keywords.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_nishang_malicious_commandlets.yml rule: remove keywords in powershell rule prone to FPs 2020-02-11 16:26:17 +01:00
powershell_ntfs_ads_access.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_prompt_credentials.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_psattack.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_remote_powershell_session.yml OSCD QA wave 3 2020-02-02 12:41:12 +01:00
powershell_shellcode_b64.yml Added UUIDs to rules 2019-11-12 23:12:27 +01:00
powershell_suspicious_download.yml fix: converted CRLF line break to LF 2020-03-25 14:36:34 +01:00
powershell_suspicious_invocation_generic.yml Typo fix for powershell_suspicious_invocation_generic.yml 2020-03-29 04:16:15 -06:00
powershell_suspicious_invocation_specific.yml fix: fixed missing date fields in remaining files 2020-01-30 16:07:37 +01:00
powershell_suspicious_keywords.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
powershell_suspicious_profile_create.yml Update powershell_suspicious_profile_create.yml 2020-04-03 09:36:17 +02:00
powershell_winlogon_helper_dll.yml Added UUIDs to rules 2019-11-12 23:12:27 +01:00
powershell_wmimplant.yml Disabled keywords that could cause FPs 2020-03-30 08:53:52 +02:00