Merge pull request #7 from yampelo/patch-1
Update powershell_malicious_commandlets.yml
This commit is contained in:
@@ -114,6 +114,7 @@ detection:
|
||||
- Invoke-PortScan
|
||||
- Invoke-ReverseDNSLookup
|
||||
- Invoke-SMBScanner
|
||||
- Invoke-Mimikittenz
|
||||
condition: keywords
|
||||
falsepositives:
|
||||
- Penetration testing
|
||||
|
||||
Reference in New Issue
Block a user