SigmaHQ/rules/windows/powershell
2021-08-26 11:15:33 +02:00
..
powershell_accessing_win_api.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_adrecon_execution.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_alternate_powershell_hosts.yml fix ContextInfo FP 2021-08-18 15:18:29 +02:00
powershell_automated_collection.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_bad_opsec_artifacts.yml Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
powershell_cl_invocation_lolscript_count.yml fix file name case 2021-08-26 11:15:33 +02:00
powershell_cl_invocation_lolscript.yml fix file name case 2021-08-26 11:15:33 +02:00
powershell_cl_mutexverifiers_lolscript_count.yml fix file name case 2021-08-26 11:15:33 +02:00
powershell_cl_mutexverifiers_lolscript.yml fix file name case 2021-08-26 11:15:33 +02:00
powershell_clear_powershell_history.yml fix powershell_clear_powershell_history error 2021-08-21 10:00:48 +02:00
powershell_create_local_user.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_data_compressed.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_decompress_commands.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_delete_volume_shadow_copies.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
powershell_detect_vm_env.yml add powershell_suspicious_win32_pnpentity 2021-08-23 13:17:35 +02:00
powershell_dnscat_execution.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_downgrade_attack.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
powershell_exe_calling_ps.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
powershell_get_clipboard.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_icmp_exfiltration.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_invoke_nightmare.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_invoke_obfuscation_clip+.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_obfuscated_iex.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_stdin+.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_var+.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_compress.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_rundll.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_stdin.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_invoke_obfuscation_via_use_clip.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_use_mhsta.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_use_rundll32.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_invoke_obfuscation_via_var++.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_keylogging.yml Spelling Errors on Rules 2021-08-18 18:58:20 +00:00
powershell_malicious_commandlets.yml Cleanup PS rules 2021-08-21 09:58:58 +02:00
powershell_malicious_keywords.yml Update PowerShell rule 2021-08-21 09:08:38 +02:00
powershell_nishang_malicious_commandlets.yml Update PowerShell rule 2021-08-21 09:08:38 +02:00
powershell_ntfs_ads_access.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_powercat.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_powerview_malicious_commandlets.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_prompt_credentials.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_psattack.yml fix powershell_psattack error 2021-08-21 10:05:47 +02:00
powershell_remote_powershell_session.yml Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
powershell_renamed_powershell.yml Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
powershell_shellcode_b64.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_shellintel_malicious_commandlets.yml Update PS rules 2021-08-21 09:33:52 +02:00
powershell_suspicious_download.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
powershell_suspicious_export_pfxcertificate.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_getprocess_lsass.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_invocation_generic.yml added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
powershell_suspicious_invocation_specific.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_keywords.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_mail_acces.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_mounted_share_deletion.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_recon.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_suspicious_win32_pnpentity.yml add powershell_suspicious_win32_pnpentity 2021-08-23 13:17:35 +02:00
powershell_tamper_with_windows_defender.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
powershell_timestomp.yml Update powershell_timestomp.yml 2021-08-05 15:46:01 +02:00
powershell_trigger_profiles.yml add powershell_trigger_profiles 2021-08-18 14:29:50 +02:00
powershell_winlogon_helper_dll.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_wmi_persistence.yml fix title 2021-08-19 16:09:31 +02:00
powershell_wmimplant.yml Update PS rules 2021-08-21 09:50:59 +02:00
powershell_wsman_com_provider_no_powershell.yml fix: Correct incorrect message / keyword usage 2021-08-12 16:28:07 +02:00
powershell_xor_commandline.yml add definition to powershell-classic 2021-08-16 12:56:24 +02:00
win_powershell_web_request.yml fix EventID: 4104 ScriptBlockText 2021-08-04 14:49:50 +02:00