This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
a036fcc2dde2c399c0d87c5401dc374b64c8a855
blue-team-tools
/
rules
/
windows
/
powershell
/
powershell_classic
T
History
Florian Roth
50b2fad091
Merge branch 'master' into aurora-false-positive-fixing
2022-06-20 13:43:36 +02:00
..
posh_pc_alternate_powershell_hosts.yml
…
posh_pc_delete_volume_shadow_copies.yml
refactor: rule level adjustments - critical to high
2022-06-18 17:43:22 +02:00
posh_pc_downgrade_attack.yml
fix: remove penetration test as valid false positive reason
2022-03-16 14:33:18 +01:00
posh_pc_exe_calling_ps.yml
fix: remove penetration test as valid false positive reason
2022-03-16 14:33:18 +01:00
posh_pc_powercat.yml
…
posh_pc_remote_powershell_session.yml
fix: FPs
2022-06-20 12:52:23 +02:00
posh_pc_renamed_powershell.yml
…
posh_pc_susp_athremotefxvgpudisablementcommand.yml
…
posh_pc_susp_download.yml
Renamed suspicious in filenames to susp
2022-05-19 09:37:04 +02:00
posh_pc_susp_get_nettcpconnection.yml
…
posh_pc_susp_zip_compress.yml
…
posh_pc_tamper_with_windows_defender.yml
…
posh_pc_wsman_com_provider_no_powershell.yml
…
posh_pc_xor_commandline.yml
…