rule :improved bloodhound rule

This commit is contained in:
Florian Roth
2019-12-20 17:23:40 +01:00
parent 0e82dce2a0
commit 0fa5ba925e
@@ -19,6 +19,7 @@ detection:
selection2:
CommandLine|contains:
- ' -CollectionMethod All '
- '.exe -c All -d '
- 'Invoke-Bloodhound'
- 'Get-BloodHoundData'
selection3: