SigmaHQ/rules/windows/powershell
2018-11-20 21:07:36 -08:00
..
powershell_downgrade_attack.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_exe_calling_ps.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_malicious_commandlets.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_malicious_keywords.yml Lower case T 2018-09-26 11:44:12 +02:00
powershell_ntfs_ads_access.yml changed .yaml files to .yml for consistency 2018-11-20 21:07:36 -08:00
powershell_prompt_credentials.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_psattack.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_shellcode_b64.yml Rule: Detect base64 encoded PowerShell shellcode 2018-11-17 09:10:09 +01:00
powershell_suspicious_download.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_suspicious_invocation_generic.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_suspicious_invocation_specific.yml Tagged windows powershell, other and malware rules. 2018-07-24 10:56:41 +02:00
powershell_xor_commandline.yml Fixed rule 2018-10-18 16:20:51 +02:00