This commit is contained in:
Michael Haag
2025-03-17 13:37:03 -06:00
parent 17f0b8e5f3
commit 71b3c2520f
7 changed files with 7 additions and 7 deletions
@@ -1,6 +1,6 @@
name: Any Powershell DownloadString
id: 4d015ef2-7adf-11eb-95da-acde48001122
version: 9
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
@@ -1,6 +1,6 @@
name: Attacker Tools On Endpoint
id: a51bfe1a-94f0-48cc-b4e4-16a110145893
version: 8
version: 9
date: '2025-02-10'
author: Bhavin Patel, Splunk
status: production
@@ -1,6 +1,6 @@
name: Detect Regsvr32 Application Control Bypass
id: 070e9b80-6252-11eb-ae93-0242ac130002
version: 9
version: 10
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
@@ -1,6 +1,6 @@
name: PowerShell WebRequest Using Memory Stream
id: 103affa6-924a-4b53-aff4-1d5075342aab
version: 4
version: 5
date: '2024-11-13'
author: Steven Dick
status: production
@@ -1,6 +1,6 @@
name: System User Discovery With Whoami
id: 894fc43e-6f50-47d5-a68b-ee9ee23e18f4
version: 4
version: 5
date: '2024-11-13'
author: Mauricio Velazco, Splunk
status: production
+1 -1
View File
@@ -1,6 +1,6 @@
name: W3WP Spawning Shell
id: 0f03423c-7c6a-11eb-bc47-acde48001122
version: 6
version: 7
date: '2025-02-10'
author: Michael Haag, Splunk
status: production
@@ -1,6 +1,6 @@
name: Windows Process Writing File to World Writable Path
id: c051b68c-60f7-4022-b3ad-773bec7a225b
version: 4
version: 5
date: '2024-11-13'
author: Michael Haag, Splunk
data_source: []