SigmaHQ/rules/windows/powershell
Thomas Patzke 08eec2b6e6
Merge pull request #1094 from NikitaStormwind/Regular30
[OSCD] Detects Obfuscated Powershell via use Rundll32 in Scripts #30 (4104, 4103)
2020-10-13 21:43:16 +02:00
..
powershell_accessing_win_api.yml Update powershell_accessing_win_api.yml 2020-10-07 14:47:29 +03:00
powershell_alternate_powershell_hosts.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_clear_powershell_history.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_cmdline_reversed_strings.yml Update powershell_cmdline_reversed_strings.yml 2020-10-11 23:40:12 +03:00
powershell_code_injection.yml Update powershell_code_injection.yml 2020-10-07 14:50:00 +03:00
powershell_create_local_user.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_data_compressed.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_dnscat_execution.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_downgrade_attack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_exe_calling_ps.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_icmp_exfiltration.yml remove redundant reference 2020-10-11 23:35:17 +02:00
powershell_invoke_obfuscation_obfuscated_iex.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_invoke_obfuscation_via_stdin.yml Detects Obfuscated Powershell via Stdin in Scripts 2020-10-12 18:47:51 +03:00
powershell_invoke_obfuscation_via_use_clip.yml Detects Obfuscated Powershell via use Clip.exe in Scripts 2020-10-09 19:37:07 +03:00
powershell_invoke_obfuscation_via_use_rundll32.yml Update powershell_invoke_obfuscation_via_use_rundll32.yml 2020-10-09 16:25:59 +03:00
powershell_invoke_obfuscation_via_var++.yml @aw350m3 style complience (: 2020-10-13 02:47:09 +03:00
powershell_malicious_commandlets.yml append authors of the update 2020-10-11 23:42:33 +02:00
powershell_malicious_keywords.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_nishang_malicious_commandlets.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_ntfs_ads_access.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_prompt_credentials.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_psattack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_remote_powershell_session.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_shellcode_b64.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_suspicious_download.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_generic.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_specific.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_keywords.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_profile_create.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_winlogon_helper_dll.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_wmimplant.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_xor_commandline.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
win_powershell_web_request.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00