change to category: ps_script

This commit is contained in:
frack113
2021-10-16 08:18:49 +02:00
parent 0ca16b18f4
commit f6b0a89161
51 changed files with 107 additions and 152 deletions
@@ -4,7 +4,7 @@ description: Detects Execution via SyncInvoke in CL_Invocation.ps1 module
status: experimental
author: oscd.community, Natalia Shornikova
date: 2020/10/14
modified: 2021/05/21
modified: 2021/10/16
references:
- https://github.com/LOLBAS-Project/LOLBAS/blob/master/yml/OSScripts/Cl_invocation.yml
- https://twitter.com/bohops/status/948061991012327424
@@ -13,11 +13,10 @@ tags:
- attack.t1216
logsource:
product: windows
service: powershell
category: ps_script
definition: Script block logging must be enabled
detection:
selection:
EventID: 4104
ScriptBlockText|contains|all:
- 'CL_Invocation.ps1'
- 'SyncInvoke'