This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
357ca31382f7a0a690d13e57d754f53d3fbc9a72
blue-team-tools
/
rules
/
windows
/
powershell
T
History
Florian Roth
c44b22b52f
Merge pull request
#1762
from frack113/redcanary_collection
...
[OSCD] Redcanary TA0009 collection
2021-08-05 15:49:10 +02:00
..
powershell_accessing_win_api.yml
…
powershell_adrecon_execution.yml
…
powershell_alternate_powershell_hosts.yml
…
powershell_automated_collection.yml
…
powershell_bad_opsec_artifacts.yml
…
powershell_CL_Invocation_LOLScript_v2.yml
…
powershell_CL_Invocation_LOLScript.yml
…
powershell_CL_Mutexverifiers_LOLScript_v2.yml
…
powershell_CL_Mutexverifiers_LOLScript.yml
…
powershell_clear_powershell_history.yml
…
powershell_cmdline_reversed_strings.yml
…
powershell_cmdline_special_characters.yml
…
powershell_cmdline_specific_comb_methods.yml
…
powershell_code_injection.yml
…
powershell_create_local_user.yml
…
powershell_data_compressed.yml
…
powershell_decompress_commands.yml
…
powershell_delete_volume_shadow_copies.yml
…
powershell_dnscat_execution.yml
…
powershell_downgrade_attack.yml
…
powershell_exe_calling_ps.yml
…
powershell_get_clipboard.yml
…
powershell_icmp_exfiltration.yml
…
powershell_invoke_obfuscation_clip+.yml
…
powershell_invoke_obfuscation_obfuscated_iex.yml
…
powershell_invoke_obfuscation_stdin+.yml
…
powershell_invoke_obfuscation_var+.yml
…
powershell_invoke_obfuscation_via_compress.yml
…
powershell_invoke_obfuscation_via_rundll.yml
…
powershell_invoke_obfuscation_via_stdin.yml
…
powershell_invoke_obfuscation_via_use_clip.yml
…
powershell_invoke_obfuscation_via_use_mhsta.yml
…
powershell_invoke_obfuscation_via_use_rundll32.yml
…
powershell_invoke_obfuscation_via_var++.yml
…
powershell_keylogging.yml
…
powershell_malicious_commandlets.yml
…
powershell_malicious_keywords.yml
…
powershell_nishang_malicious_commandlets.yml
…
powershell_ntfs_ads_access.yml
…
powershell_powercat.yml
…
powershell_powerview_malicious_commandlets.yml
…
powershell_prompt_credentials.yml
…
powershell_psattack.yml
…
powershell_remote_powershell_session.yml
…
powershell_renamed_powershell.yml
…
powershell_shellcode_b64.yml
…
powershell_suspicious_download.yml
…
powershell_suspicious_export_pfxcertificate.yml
…
powershell_suspicious_getprocess_lsass.yml
…
powershell_suspicious_invocation_generic.yml
…
powershell_suspicious_invocation_specific.yml
…
powershell_suspicious_keywords.yml
…
powershell_suspicious_mail_acces.yml
…
powershell_suspicious_mounted_share_deletion.yml
…
powershell_suspicious_profile_create.yml
…
powershell_suspicious_recon.yml
…
powershell_tamper_with_windows_defender.yml
…
powershell_timestomp.yml
Update powershell_timestomp.yml
2021-08-05 15:46:01 +02:00
powershell_winlogon_helper_dll.yml
…
powershell_wmimplant.yml
…
powershell_wsman_com_provider_no_powershell.yml
…
powershell_xor_commandline.yml
…
poweshell_detect_vm_env.yml
Update poweshell_detect_vm_env.yml
2021-08-05 15:47:29 +02:00
win_powershell_web_request.yml
…