Merge pull request #569 from Neo23x0/devel
rule: improved bloodhound rule
This commit is contained in:
@@ -19,6 +19,7 @@ detection:
|
||||
selection2:
|
||||
CommandLine|contains:
|
||||
- ' -CollectionMethod All '
|
||||
- '.exe -c All -d '
|
||||
- 'Invoke-Bloodhound'
|
||||
- 'Get-BloodHoundData'
|
||||
selection3:
|
||||
|
||||
Reference in New Issue
Block a user