SwiftOnSecurity / sysmon-config

Sysmon configuration file template with default high-quality event tracing
4.68k stars 1.69k forks source link

Add pwsh.exe to list of suspicious Windows tools #176

Open connorcarnes opened 1 year ago

connorcarnes commented 1 year ago

PowerShell versions 6 and above use the executable pwsh.exe instead of powershell.exe:

pwsh.exe doesn't come installed by default like powershell.exe but I thought it may still be worth adding to the list of "Suspicious Windows tools" in the NetworkConnect rule group.