SigmaHQ/rules/windows/powershell
2021-07-17 09:50:11 +02:00
..
powershell_accessing_win_api.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_adrecon_execution.yml increased level 2021-07-17 09:50:11 +02:00
powershell_alternate_powershell_hosts.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_bad_opsec_artifacts.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_CL_Invocation_LOLScript_v2.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_CL_Invocation_LOLScript.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_CL_Mutexverifiers_LOLScript_v2.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_CL_Mutexverifiers_LOLScript.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_clear_powershell_history.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_cmdline_reversed_strings.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_cmdline_special_characters.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_cmdline_specific_comb_methods.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_code_injection.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_create_local_user.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00
powershell_data_compressed.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_decompress_commands.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_delete_volume_shadow_copies.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_dnscat_execution.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_downgrade_attack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_exe_calling_ps.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_get_clipboard.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_icmp_exfiltration.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_clip+.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_obfuscated_iex.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_invoke_obfuscation_stdin+.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_var+.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_compress.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_rundll.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_stdin.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_use_clip.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_use_mhsta.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_use_rundll32.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_invoke_obfuscation_via_var++.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_malicious_commandlets.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_malicious_keywords.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_nishang_malicious_commandlets.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_ntfs_ads_access.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_powerview_malicious_commandlets.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_prompt_credentials.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_psattack.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_remote_powershell_session.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_shellcode_b64.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_download.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_export_pfxcertificate.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_getprocess_lsass.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_invocation_generic.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_specific.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_keywords.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_mounted_share_deletion.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_suspicious_profile_create.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_tamper_with_windows_defender.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_winlogon_helper_dll.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_wmimplant.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_wsman_com_provider_no_powershell.yml Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell_xor_commandline.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
win_powershell_web_request.yml att&ck tags review: windows/powershell, windows/process_access, windows/network_connection 2020-08-24 23:31:26 +00:00