Closed rc-csmith closed 1 year ago
Looks good! Tested with the following rule.
status: test
description: Detects PowerShell Use
author: 'Test'
date: 2023/07/28
logsource:
category: file_event
product: windows
detection:
selection:
Image|contains:
- 'powershell.exe'
condition: selection
Changes
common.sigma_translation
a list of YML-formatted strings or a list of files