chainguard-dev / bincapz

detect malicious program behaviors
Apache License 2.0
387 stars 24 forks source link

powershell: detect verbose hidden incantation #163

Closed tstromberg closed 2 months ago

tstromberg commented 3 months ago

Add a second rule for powershell hidden windows that use the verbose invocation form. This is less suspicious than the shorter one.