Files
2020-09-07 13:18:03 +02:00

8 lines
311 B
YAML

name: Obfuscated Files or Information
detections:
- name: Malicious PowerShell Process - Encoded Command
pass_condition: '| stats count | where count > 0'
description: Test detections for Obfuscated Files or Information
target: default-attack-range-windows-domain-controller
simulation_technique: 'T1027'