Files
splunk-security_content/macros/process_powershell.yml
Nasreddine Bencherchali efa8b09ad3 update powershell analytics
2025-01-14 19:34:31 +01:00

3 lines
415 B
YAML

definition: (Processes.process_name=pwsh.exe OR Processes.process_name=powershell.exe OR Processes.process_name=powershell_ise.exe OR Processes.original_file_name=pwsh.dll OR Processes.original_file_name=PowerShell.EXE OR Processes.original_file_name=powershell_ise.EXE)
description: Matches the process with its original file name, data for this macro came from https://strontic.github.io/
name: process_powershell