mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
version
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
name: Any Powershell DownloadString
|
||||
id: 4d015ef2-7adf-11eb-95da-acde48001122
|
||||
version: 9
|
||||
version: 10
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Attacker Tools On Endpoint
|
||||
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
|
||||
version: 8
|
||||
version: 9
|
||||
date: '2025-02-10'
|
||||
author: Bhavin Patel, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Detect Regsvr32 Application Control Bypass
|
||||
id: 070e9b80-6252-11eb-ae93-0242ac130002
|
||||
version: 9
|
||||
version: 10
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: PowerShell WebRequest Using Memory Stream
|
||||
id: 103affa6-924a-4b53-aff4-1d5075342aab
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
author: Steven Dick
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: System User Discovery With Whoami
|
||||
id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
author: Mauricio Velazco, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: W3WP Spawning Shell
|
||||
id: 0f03423c-7c6a-11eb-bc47-acde48001122
|
||||
version: 6
|
||||
version: 7
|
||||
date: '2025-02-10'
|
||||
author: Michael Haag, Splunk
|
||||
status: production
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
name: Windows Process Writing File to World Writable Path
|
||||
id: c051b68c-60f7-4022-b3ad-773bec7a225b
|
||||
version: 4
|
||||
version: 5
|
||||
date: '2024-11-13'
|
||||
author: Michael Haag, Splunk
|
||||
data_source: []
|
||||
|
||||
Reference in New Issue
Block a user