Removed ATT&CK technique ids from titles and added tags
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
title: T1086 Remote PowerShell Session
|
||||
title: Remote PowerShell Session
|
||||
id: 96b9f619-aa91-478f-bacb-c3e50f8df575
|
||||
description: Detects remote PowerShell sessions
|
||||
status: experimental
|
||||
@@ -7,6 +7,9 @@ modified: 2019/11/10
|
||||
author: Roberto Rodriguez @Cyb3rWard0g
|
||||
references:
|
||||
- https://github.com/Cyb3rWard0g/ThreatHunter-Playbook/tree/master/playbooks/windows/02_execution/T1086_powershell/powershell_remote_session.md
|
||||
tags:
|
||||
- attack.execution
|
||||
- attack.t1086
|
||||
logsource:
|
||||
product: windows
|
||||
service: powershell
|
||||
@@ -20,4 +23,4 @@ detection:
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Unknown
|
||||
level: critical
|
||||
level: critical
|
||||
|
||||
Reference in New Issue
Block a user