Samirbous
|
16a49b3278
|
[New Rule] Windows Script Executing a Process via WMI (#643)
* [New Rule] Windows Script Executing a Process via WMI
* Update execution_scripts_process_started_via_wmi.toml
* Update execution_scripts_process_started_via_wmi.toml
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
* increased maxspan
* eql syntax
* deleted ecs_version
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
* Update rules/windows/execution_scripts_process_started_via_wmi.toml
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com>
Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
Co-authored-by: David French <56409778+threat-punter@users.noreply.github.com>
|
2020-12-08 19:23:48 +01:00 |
|