Files
blue-team-tools/rules/windows/process_creation
Josh 8254c4f36d Merge PR #4955 from @joshnck - Fix agentexecutor.exe related rules
fix: AgentExecutor PowerShell Execution - Exclude `Microsoft.Management.Services.IntuneWindowsAgent.exe`
fix: Suspicious AgentExecutor PowerShell Execution - Exclude `Microsoft.Management.Services.IntuneWindowsAgent.exe` 

---------

Co-authored-by: nasbench <8741929+nasbench@users.noreply.github.com>
2024-08-07 16:01:47 +02:00
..