We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 8e10a4c commit d3b8a95Copy full SHA for d3b8a95
_lolbas/Binaries/Runscripthelper.md
@@ -19,8 +19,8 @@ Code_Sample:
19
Detection:
20
- Sigma: https://github.com/SigmaHQ/sigma/blob/c04bef2fbbe8beff6c7620d5d7ea6872dbe7acba/rules/windows/process_creation/proc_creation_win_lolbin_runscripthelper.yml
21
- BlockRule: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/microsoft-recommended-block-rules
22
- - IOC: Event 4014 - Powershell logging
23
- - IOC: Event 400
+ - IOC: Event ID 4104 - Microsoft-Windows-PowerShell/Operational
+ - IOC: Event ID 400 - Windows PowerShell
24
Resources:
25
- Link: https://posts.specterops.io/bypassing-application-whitelisting-with-runscripthelper-exe-1906923658fc
26
Acknowledgement:
0 commit comments