Merge pull request #572 from alessiodallapiazza/master

Add the ability to detect PowerUp - Invoke-AllChecks
This commit is contained in:
Florian Roth
2019-12-23 12:57:55 +01:00
committed by GitHub
@@ -110,6 +110,7 @@ detection:
- "*Invoke-ReverseDNSLookup*"
- "*Invoke-SMBScanner*"
- "*Invoke-Mimikittenz*"
- "*Invoke-AllChecks*"
false_positives:
- Get-SystemDriveInfo # http://bheltborg.dk/Windows/WinSxS/amd64_microsoft-windows-maintenancediagnostic_31bf3856ad364e35_10.0.10240.16384_none_91ef7543a4514b5e/CL_Utility.ps1
condition: keywords and not false_positives