Files
Patrick Bareiss 074b782dd0 detection tested
2020-07-28 15:43:57 +02:00

8 lines
303 B
YAML

name: Obfuscated Files or Information
detections:
- name: Malicious PowerShell Process - Encoded Command
pass_condition: '| stats count | where count > 0'
description: Test detections for Obfuscated Files or Information
target: attack-range-windows-domain-controller
simulation_technique: 'T1027'