Files
blue-team-tools/rules/windows/process_creation
OpalSec ca09ae5039 Modification of search logic per advice from @zinint
Edited suggested searches to improve performance:

VAR+
16ms:	.*cmd.*(?:\/c|\/r).*set.*(?:\{\d\}){1,}\\\"\s+?\-f(?:.*\)){1,}.*\"

6ms:  .*cmd.{0,5}(?:\/c|\/r)(?:\s|)\"set\s[a-zA-Z]{3,6}.*(?:\{\d\}){1,}\\\"\s+?\-f(?:.*\)){1,}.*\"

STDIN+
7ms:    .*cmd.*(?:\/c|\/r).*powershell.+(?:\$\{?input}?|noexit).*\"

3ms:    .*cmd.{0,5}(?:\/c|\/r).+powershell.+(?:\$\{?input\}?|noexit).+\"

CLIP+
28ms:    .*cmd.*(?:\/c|\/r).*\|.*clip(?:\.exe)?.*&&.*clipboard]::\(\s\\\"\{\d\}.*\-f.*\"

11ms:    .*cmd.{0,5}(?:\/c|\/r).+clip(?:\.exe)?.{0,4}&&.+clipboard]::\(\s\\\"\{\d\}.+\-f.+\"
2020-10-18 21:15:43 +11:00
..
2020-02-07 15:47:27 +01:00
2020-02-02 12:41:12 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-09-03 09:18:28 +02:00
2019-11-12 23:12:27 +01:00
2020-01-11 00:11:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00
2019-11-12 23:12:27 +01:00
2020-09-13 15:46:45 +02:00
2020-10-09 09:26:01 +03:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-10-09 11:59:08 +03:00
2019-11-12 23:12:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00