Skip to content

Commit 16db378

Browse files
committed
++, powershell.file.*
1 parent f7c355a commit 16db378

13 files changed

+13
-78
lines changed

rules/windows/defense_evasion_posh_obfuscation_backtick.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -104,12 +104,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
104104
| keep
105105
Esql.script_block_pattern_count,
106106
Esql.script_block_tmp,
107-
powershell.file.script_block_text,
108-
powershell.file.script_block_id,
109-
powershell.file.script_block_entropy_bits,
110-
powershell.file.script_block_surprisal_stdev,
111-
powershell.file.script_block_length,
112-
powershell.file.script_block_unique_symbols,
107+
powershell.file.*
113108
file.name,
114109
file.directory,
115110
file.path,

rules/windows/defense_evasion_posh_obfuscation_backtick_var.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -103,12 +103,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
103103
Esql.script_block_pattern_count,
104104
Esql.script_block_length,
105105
Esql.script_block_tmp,
106-
powershell.file.script_block_text,
107-
powershell.file.script_block_id,
108-
powershell.file.script_block_entropy_bits,
109-
powershell.file.script_block_surprisal_stdev,
110-
powershell.file.script_block_length,
111-
powershell.file.script_block_unique_symbols,
106+
powershell.file.*
112107
file.path,
113108
file.name,
114109
powershell.sequence,

rules/windows/defense_evasion_posh_obfuscation_char_arrays.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -105,12 +105,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
105105
| keep
106106
Esql.script_block_pattern_count,
107107
Esql.script_block_tmp,
108-
powershell.file.script_block_text,
109-
powershell.file.script_block_id,
110-
powershell.file.script_block_entropy_bits,
111-
powershell.file.script_block_surprisal_stdev,
112-
powershell.file.script_block_length,
113-
powershell.file.script_block_unique_symbols,
108+
powershell.file.*
114109
file.path,
115110
powershell.sequence,
116111
powershell.total,

rules/windows/defense_evasion_posh_obfuscation_concat_dynamic.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -101,12 +101,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
101101
| keep
102102
Esql.script_block_pattern_count,
103103
Esql.script_block_tmp,
104-
powershell.file.script_block_text,
105-
powershell.file.script_block_id,
106-
powershell.file.script_block_entropy_bits,
107-
powershell.file.script_block_surprisal_stdev,
108-
powershell.file.script_block_length,
109-
powershell.file.script_block_unique_symbols,
104+
powershell.file.*
110105
file.path,
111106
powershell.sequence,
112107
powershell.total,

rules/windows/defense_evasion_posh_obfuscation_high_number_proportion.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -106,12 +106,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
106106
Esql.script_block_ratio,
107107
Esql.script_block_length,
108108
Esql.script_block_tmp,
109-
powershell.file.script_block_text,
110-
powershell.file.script_block_id,
111-
powershell.file.script_block_entropy_bits,
112-
powershell.file.script_block_surprisal_stdev,
113-
powershell.file.script_block_length,
114-
powershell.file.script_block_unique_symbols,
109+
powershell.file.*
115110
file.directory,
116111
file.path,
117112
powershell.sequence,

rules/windows/defense_evasion_posh_obfuscation_iex_env_vars_reconstruction.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -106,12 +106,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
106106
Esql.script_block_pattern_count,
107107
Esql.script_block_length,
108108
Esql.script_block_tmp,
109-
powershell.file.script_block_text,
110-
powershell.file.script_block_id,
111-
powershell.file.script_block_entropy_bits,
112-
powershell.file.script_block_surprisal_stdev,
113-
powershell.file.script_block_length,
114-
powershell.file.script_block_unique_symbols,
109+
powershell.file.*
115110
file.path,
116111
powershell.sequence,
117112
powershell.total,

rules/windows/defense_evasion_posh_obfuscation_iex_string_reconstruction.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -107,12 +107,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
107107
Esql.script_block_pattern_count,
108108
Esql.script_block_length,
109109
Esql.script_block_tmp,
110-
powershell.file.script_block_text,
111-
powershell.file.script_block_id,
112-
powershell.file.script_block_entropy_bits,
113-
powershell.file.script_block_surprisal_stdev,
114-
powershell.file.script_block_length,
115-
powershell.file.script_block_unique_symbols,
110+
powershell.file.*
116111
file.path,
117112
file.directory,
118113
powershell.sequence,

rules/windows/defense_evasion_posh_obfuscation_index_reversal.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -108,12 +108,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
108108
Esql.script_block_pattern_count,
109109
Esql.script_block_length,
110110
Esql.script_block_tmp,
111-
powershell.file.script_block_text,
112-
powershell.file.script_block_id,
113-
powershell.file.script_block_entropy_bits,
114-
powershell.file.script_block_surprisal_stdev,
115-
powershell.file.script_block_length,
116-
powershell.file.script_block_unique_symbols,
111+
powershell.file.*
117112
file.path,
118113
powershell.sequence,
119114
powershell.total,

rules/windows/defense_evasion_posh_obfuscation_reverse_keyword.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -104,12 +104,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
104104
| keep
105105
Esql.script_block_pattern_count,
106106
Esql.script_block_tmp,
107-
powershell.file.script_block_text,
108-
powershell.file.script_block_id,
109-
powershell.file.script_block_entropy_bits,
110-
powershell.file.script_block_surprisal_stdev,
111-
powershell.file.script_block_length,
112-
powershell.file.script_block_unique_symbols,
107+
powershell.file.*
113108
file.path,
114109
powershell.sequence,
115110
powershell.total,

rules/windows/defense_evasion_posh_obfuscation_string_concat.toml

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -106,12 +106,7 @@ from logs-windows.powershell_operational* metadata _id, _version, _index
106106
Esql.script_block_pattern_count,
107107
Esql.script_block_length,
108108
Esql.script_block_tmp,
109-
powershell.file.script_block_text,
110-
powershell.file.script_block_id,
111-
powershell.file.script_block_entropy_bits,
112-
powershell.file.script_block_surprisal_stdev,
113-
powershell.file.script_block_length,
114-
powershell.file.script_block_unique_symbols,
109+
powershell.file.*
115110
file.path,
116111
powershell.sequence,
117112
powershell.total,

0 commit comments

Comments
 (0)