refactor: PowerShell Defender modifications
This commit is contained in:
@@ -24,10 +24,11 @@ detection:
|
||||
- DisableBehaviorMonitoring
|
||||
- DisableScriptScanning
|
||||
- DisableBlockAtFirstSeen
|
||||
- DisableIOAVProtection
|
||||
condition: selection
|
||||
falsepositives:
|
||||
- Legitimate PowerShell scripts
|
||||
level: medium
|
||||
level: high
|
||||
tags:
|
||||
- attack.defense_evasion
|
||||
- attack.t1562.001
|
||||
|
||||
Reference in New Issue
Block a user