cridin1 / pwsh-execution-analysis

Analyzing PowerShell execution on Windows systems.
1 stars 0 forks source link

Better execution analysis with refined rules #4

Open cridin1 opened 1 month ago

cridin1 commented 1 month ago

https://stackoverflow.com/questions/78876980/threat-detection-with-sysmon-csv-log-using-sigma-rules

cridin1 commented 1 month ago

Objective: Improve execution analysis by mapping each script with TTPs and specific rules for each TTP