mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
5.0 KiB
5.0 KiB
title, last_modified_at, toc, tags
| title | last_modified_at | toc | tags | ||||
|---|---|---|---|---|---|---|---|
| Malicious PowerShell | 2017-08-23 | true |
|
Description
Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent.
- ID: 2c8ff66e-0b57-42af-8ad7-912438a403fc
- Product: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud
- Datamodel: Endpoint
- Last Updated: 2017-08-23
- Author: David Dorsey, Splunk
Detection profiles
Reference
- https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/
- https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/
source | version: 5