Files
splunk-security_content/lookups/malicious_powershell_strings.yml
2025-03-03 16:20:52 -08:00

13 lines
337 B
YAML

name: malicious_powershell_strings
date: 2025-03-03
version: 2
id: d2fcf9eb-c7a4-4b05-9db4-99c6430d0513
author: Steven Dick
lookup_type: csv
description: A list of commands and commandlets used with known malicious powershell tooling.
match_type:
- WILDCARD(command)
min_matches: 1
max_matches: 1
case_sensitive_match: false