change to category: ps_script

This commit is contained in:
frack113
2021-10-16 08:18:49 +02:00
parent 0ca16b18f4
commit f6b0a89161
51 changed files with 107 additions and 152 deletions
@@ -13,14 +13,13 @@ tags:
- attack.t1086 #an old one
author: David Ledbetter (shellcode), Florian Roth (rule)
date: 2018/11/17
modified: 2020/12/01
modified: 2021/10/16
logsource:
product: windows
service: powershell
category: ps_script
definition: Script block logging must be enabled
detection:
selection:
EventID: 4104
ScriptBlockText|contains: 'AAAAYInlM'
selection2:
ScriptBlockText|contains: