SigmaHQ/rules/windows/powershell
2020-07-07 22:54:55 +02:00
..
powershell_alternate_powershell_hosts.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_clear_powershell_history.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_create_local_user.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_data_compressed.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_dnscat_execution.yml Rule fixes 2020-02-20 23:00:16 +01:00
powershell_downgrade_attack.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_exe_calling_ps.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_invoke_obfuscation_obfuscated_iex.yml Rule fixes 2020-02-20 23:00:16 +01:00
powershell_malicious_commandlets.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_malicious_keywords.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_nishang_malicious_commandlets.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_ntfs_ads_access.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_prompt_credentials.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_psattack.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_remote_powershell_session.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_shellcode_b64.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_suspicious_download.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_suspicious_invocation_generic.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_suspicious_invocation_specific.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_suspicious_keywords.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_suspicious_profile_create.yml Update powershell_suspicious_profile_create.yml 2020-04-03 09:36:17 +02:00
powershell_winlogon_helper_dll.yml Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell_wmimplant.yml Disabled keywords that could cause FPs 2020-03-30 08:53:52 +02:00
powershell_xor_commandline.yml Added new rule for pwsh_xor_cmd 2020-06-29 22:09:58 +02:00
win_powershell_web_request.yml Added rule id 2020-07-07 22:54:55 +02:00