SigmaHQ/rules/windows/powershell
2021-07-06 20:56:31 +08:00
..
powershell_accessing_win_api.yml Update powershell_accessing_win_api.yml 2020-10-07 14:47:29 +03:00
powershell_alternate_powershell_hosts.yml Set powershell_alternate_powershell_hosts.yml more accurate by adding the correct channel for EventID 2021-06-01 10:47:17 +02:00
powershell_bad_opsec_artifacts.yml Powershell artefacts to critical 2021-06-10 09:42:07 +02:00
powershell_CL_Invocation_LOLScript_v2.yml Fix falsepositives list 2021-05-21 12:29:28 +02:00
powershell_CL_Invocation_LOLScript.yml Fix falsepositives list 2021-05-21 12:31:01 +02:00
powershell_CL_Mutexverifiers_LOLScript_v2.yml Fix falsepositives list 2021-05-21 12:26:37 +02:00
powershell_CL_Mutexverifiers_LOLScript.yml Fix falsepositives list 2021-05-21 12:28:12 +02:00
powershell_clear_powershell_history.yml Update powershell_clear_powershell_history.yml 2020-11-28 09:26:18 +01:00
powershell_cmdline_reversed_strings.yml Update powershell_cmdline_reversed_strings.yml 2020-10-11 23:40:12 +03:00
powershell_cmdline_special_characters.yml fix: missing new line placeholder escape 2021-04-09 16:45:07 +02:00
powershell_cmdline_specific_comb_methods.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_code_injection.yml Clean-up service: sysmon as it will be replaced by filling the category 2021-04-15 02:02:25 +02:00
powershell_create_local_user.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_data_compressed.yml Insert modified date 2021-07-06 20:56:31 +08:00
powershell_decompress_commands.yml Fixes&improvements 2021-04-08 01:06:40 +02:00
powershell_delete_volume_shadow_copies.yml Add t1490 powershell delete volume shadow copie 2021-06-03 22:39:06 +02:00
powershell_dnscat_execution.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_downgrade_attack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_exe_calling_ps.yml Update powershell_exe_calling_ps.yml 2020-10-15 17:09:47 -03:00
powershell_get_clipboard.yml 16 rules from DH APT29 day 1 - contributing soon 2020-10-12 18:13:13 -04:00
powershell_icmp_exfiltration.yml remove redundant reference 2020-10-11 23:35:17 +02:00
powershell_invoke_obfuscation_clip+.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_obfuscated_iex.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_invoke_obfuscation_stdin+.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_var+.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_compress.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_rundll.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_stdin.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_use_clip.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_use_mhsta.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_use_rundll32.yml Fixes and improvements 2021-04-03 00:08:55 +02:00
powershell_invoke_obfuscation_via_var++.yml fix: duplicate UUIDs 2021-05-27 10:29:21 +02:00
powershell_malicious_commandlets.yml Update powershell_malicious_commandlets.yml 2020-10-15 20:59:27 -03:00
powershell_malicious_keywords.yml Update powershell_malicious_keywords.yml 2020-10-15 17:12:08 -03:00
powershell_nishang_malicious_commandlets.yml docs: changed modification date 2021-04-23 14:55:04 +02:00
powershell_ntfs_ads_access.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_powerview_malicious_commandlets.yml fix: bug in syntax 2021-07-03 13:19:56 +02:00
powershell_prompt_credentials.yml Update powershell_prompt_credentials.yml 2020-10-15 17:13:16 -03:00
powershell_psattack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_remote_powershell_session.yml Update Threat Hunter Playbook Reference 2021-05-22 01:03:49 -03:00
powershell_renamed_powershell.yml fix pr 869 2021-07-04 19:44:50 +02:00
powershell_shellcode_b64.yml Fixes 2021-04-03 23:21:13 +02:00
powershell_suspicious_download.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_export_pfxcertificate.yml fix: fixed rule title 2021-04-23 09:51:31 +02:00
powershell_suspicious_getprocess_lsass.yml Update powershell_suspicious_getprocess_lsass.yml 2021-05-04 14:04:52 +03:00
powershell_suspicious_invocation_generic.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_specific.yml Improve Logic 2020-11-20 01:22:20 -03:00
powershell_suspicious_keywords.yml more PowerShell suspicious keywords 2021-06-10 09:41:55 +02:00
powershell_suspicious_mounted_share_deletion.yml Update powershell_suspicious_mounted_share_deletion.yml 2020-10-07 17:54:48 +11:00
powershell_suspicious_profile_create.yml - Cleaned up some more rules where 'service: sysmon' was combined with category 2020-10-02 10:45:29 +02:00
powershell_tamper_with_windows_defender.yml Split original to existing file 2021-06-07 20:27:14 +02:00
powershell_winlogon_helper_dll.yml Updated ART reference links from .yaml to .md and sub-technique links. 2021-07-06 17:21:22 +08:00
powershell_wmimplant.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_wsman_com_provider_no_powershell.yml Fix falsepositives list 2021-05-21 12:24:25 +02:00
powershell_xor_commandline.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
win_powershell_web_request.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00