Update powershell_cmdline_special_characters.yml

This commit is contained in:
Vasiliy Burov
2020-10-15 19:39:24 +03:00
committed by GitHub
parent 1b0d4e546f
commit fa7036430e
@@ -17,11 +17,12 @@ logsource:
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|re: '.*`.*`.*`.*`.*`.*'
CommandLine|re: '.*^.*^.*^.*^.*^.*'
CommandLine|re: '.*{.*{.*{.*{.*{.*'
CommandLine|re: '.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*'
CommandLine|re: '.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*'
CommandLine|re:
- '.*`.*`.*`.*`.*`.*'
- '.*^.*^.*^.*^.*^.*'
- '.*{.*{.*{.*{.*{.*'
- '.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*\{.*'
- '.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*\+.*'
condition: selection
falsepositives:
- Unlikely