We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 8bd57a5 commit 32316b0Copy full SHA for 32316b0
yml/OSBinaries/Powershell.yml
@@ -14,3 +14,6 @@ Commands:
14
OperatingSystem: Windows 10, Windows 11
15
Full_Path:
16
- Path: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
17
+Detection:
18
+ - IOA: Multiple TCP SYN packets to sequential ports from a single source IP.
19
+ - IOA: High rate of connection attempts to closed ports.
0 commit comments