Samirbous
497ddcbb58
[New Rule] Suspicious Python Script Execution via the CommandLine ( #852 )
...
* [New Rule] Suspicious Python Script Execution via the CommandLine
* kql optimz
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
* added subtechnique
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
* converted to eql
* Update rules/cross-platform/execution_python_script_in_cmdline.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
* relinted
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com >
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com >
2021-02-10 18:37:03 +01:00