mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
13 lines
337 B
YAML
13 lines
337 B
YAML
name: malicious_powershell_strings
|
|
date: 2025-03-03
|
|
version: 2
|
|
id: d2fcf9eb-c7a4-4b05-9db4-99c6430d0513
|
|
author: Steven Dick
|
|
lookup_type: csv
|
|
description: A list of commands and commandlets used with known malicious powershell tooling.
|
|
match_type:
|
|
- WILDCARD(command)
|
|
min_matches: 1
|
|
max_matches: 1
|
|
case_sensitive_match: false
|