Update powershell_invoke_obfuscation_via_use_rundll32.yml

This commit is contained in:
Nikita Nazarov
2020-10-08 17:36:20 +03:00
committed by GitHub
parent 2db2ab30c4
commit 3ba4eeac7b
@@ -4,7 +4,7 @@ description: Detects Obfuscated Powershell via use Rundll32 in Scripts
status: experimental
author: Nikita Nazarov, oscd.community
date: 2019/10/08
references: https://github.com/Neo23x0/sigma/issues/1009
references: -https://github.com/Neo23x0/sigma/issues/1009
tags:
- attack.defense_evasion
- attack.t1027