Update ssa___windows_powershell_connect_to_internet_with_hidden_window.yml

This commit is contained in:
Bhavin Patel
2022-02-15 12:37:57 -08:00
committed by GitHub
parent 59292cf55e
commit 6ef8187b2f
@@ -5,7 +5,7 @@ date: '2022-02-11'
author: Jose Hernandez, David Dorsey, Michael Haag Splunk
type: Anomaly
datamodel:
- Endpoint
- Endpoint_Processes
description: The following hunting analytic identifies PowerShell commands utilizing
the WindowStyle parameter to hide the window on the compromised endpoint. This combination
of command-line options is suspicious because it is overriding the default PowerShell
@@ -94,4 +94,4 @@ tags:
- cmd_line
risk_score: 35
risk_severity: low
security_domain: endpoint
security_domain: endpoint