Samirbous
|
497ddcbb58
|
[New Rule] Suspicious Python Script Execution via the CommandLine (#852)
* [New Rule] Suspicious Python Script Execution via the CommandLine
* kql optimz
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* added subtechnique
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
* converted to eql
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
* relinted
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
|
2021-02-10 18:37:03 +01:00 |
|