SigmaHQ / sigma

Main Sigma Rule Repository
Other
8.19k stars 2.17k forks source link

fix: filter PS1 policy check for AppLocker mode #4797

Closed phantinuss closed 5 months ago

phantinuss commented 5 months ago

Summary of the Pull Request

fix: add filter for automatic execution of a policy test for PowerShell AppLocker lockdown mode

Changelog

fix: Windows Binaries Write Suspicious Extensions - filter PS1 policy check for AppLocker mode

Example Log Event

Fixed Issues

SigmaHQ Rule Creation Conventions