Files
splunk-security_content/lookups/malicious_powershell_strings.yml
Raven Tait 917fe77cc0 Add Big Batch of Snap Attack Converted Rules (#4015)
---------

Co-authored-by: Nasreddine Bencherchali <nasreddineb@splunk.com>
Co-authored-by: Bhavin Patel <bpatel@splunk.com>
2026-05-05 16:11:18 +02:00

13 lines
337 B
YAML

name: malicious_powershell_strings
date: 2025-05-05
version: 3
id: d2fcf9eb-c7a4-4b05-9db4-99c6430d0513
author: Steven Dick, Raven Tait
lookup_type: csv
description: A list of commands and commandlets used with known malicious powershell tooling.
match_type:
- WILDCARD(command)
min_matches: 1
max_matches: 1
case_sensitive_match: false