From 6ef8187b2f6d7c2a8e0bbe38ea55b2183f91e8fb Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Tue, 15 Feb 2022 12:37:57 -0800 Subject: [PATCH] Update ssa___windows_powershell_connect_to_internet_with_hidden_window.yml --- ...dows_powershell_connect_to_internet_with_hidden_window.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml b/detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml index ea4db54aa5..b07c391fab 100644 --- a/detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml +++ b/detections/endpoint/ssa___windows_powershell_connect_to_internet_with_hidden_window.yml @@ -5,7 +5,7 @@ date: '2022-02-11' author: Jose Hernandez, David Dorsey, Michael Haag Splunk type: Anomaly datamodel: -- Endpoint +- Endpoint_Processes description: The following hunting analytic identifies PowerShell commands utilizing the WindowStyle parameter to hide the window on the compromised endpoint. This combination of command-line options is suspicious because it is overriding the default PowerShell @@ -94,4 +94,4 @@ tags: - cmd_line risk_score: 35 risk_severity: low - security_domain: endpoint \ No newline at end of file + security_domain: endpoint