Skip to content

Commit 32316b0

Browse files
authored
Update Powershell.yml
1 parent 8bd57a5 commit 32316b0

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

yml/OSBinaries/Powershell.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -14,3 +14,6 @@ Commands:
1414
OperatingSystem: Windows 10, Windows 11
1515
Full_Path:
1616
- Path: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
17+
Detection:
18+
- IOA: Multiple TCP SYN packets to sequential ports from a single source IP.
19+
- IOA: High rate of connection attempts to closed ports.

0 commit comments

Comments
 (0)