ef7548f04c
* Update collection_email_powershell_exchange_mailbox.toml * Update command_and_control_remote_file_copy_powershell.toml * Update defense_evasion_disabling_windows_defender_powershell.toml * Update execution_scheduled_task_powershell_source.toml * Update execution_via_compiled_html_file.toml * Update impact_volume_shadow_copy_deletion_via_powershell.toml * Update initial_access_suspicious_ms_exchange_worker_child_process.toml * Update persistence_powershell_exch_mailbox_activesync_add_device.toml * Update persistence_webshell_detection.toml * Update defense_evasion_execution_msbuild_started_by_script.toml * Update defense_evasion_clearing_windows_event_logs.toml * Update defense_evasion_suspicious_zoom_child_process.toml * Update defense_evasion_defender_exclusion_via_powershell.toml * Update persistence_local_scheduled_task_scripting.toml * Update persistence_local_scheduled_task_creation.toml * Update persistence_system_shells_via_services.toml * Update collection_email_powershell_exchange_mailbox.toml * Update command_and_control_remote_file_copy_powershell.toml * Update defense_evasion_clearing_windows_event_logs.toml * Update defense_evasion_defender_exclusion_via_powershell.toml * Update defense_evasion_disabling_windows_defender_powershell.toml * Update defense_evasion_execution_msbuild_started_by_script.toml * Update defense_evasion_suspicious_zoom_child_process.toml * Update execution_scheduled_task_powershell_source.toml * Update execution_via_compiled_html_file.toml * Update impact_volume_shadow_copy_deletion_via_powershell.toml * Update initial_access_suspicious_ms_exchange_worker_child_process.toml * Update persistence_local_scheduled_task_creation.toml * Update persistence_local_scheduled_task_scripting.toml * Update persistence_powershell_exch_mailbox_activesync_add_device.toml * Update persistence_system_shells_via_services.toml * Update persistence_webshell_detection.toml * Update rules/windows/persistence_local_scheduled_task_creation.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/initial_access_suspicious_ms_exchange_worker_child_process.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/defense_evasion_disabling_windows_defender_powershell.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> * Update rules/windows/defense_evasion_defender_exclusion_via_powershell.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Jonhnathan <jonhnathancesar@gmail.com>