File tree Expand file tree Collapse file tree 1 file changed +1
-3
lines changed
Expand file tree Collapse file tree 1 file changed +1
-3
lines changed Original file line number Diff line number Diff line change 22creation_date = " 2023/01/17"
33integration = [" windows" ]
44maturity = " production"
5- updated_date = " 2025/02/03 "
5+ updated_date = " 2025/02/21 "
66min_stack_version = " 8.14.0"
77min_stack_comments = " Breaking change at 8.14.0 for the Windows Integration."
88
@@ -131,9 +131,7 @@ event.category:"process" and host.os.type:windows and
131131 "AllocHGlobal((9076" or
132132 "[cHAr](65)+[cHaR]([byTe]0x6d)+[ChaR]([ByTe]0x73)+[CHaR]([BYte]0x69"
133133 ) or
134- powershell.file.script_block_text:("[System.Runtime.InteropServices.Marshal]::Copy" and "VirtualProtect") or
135134 powershell.file.script_block_text:("[Ref].Assembly.GetType(('System.Management.Automation" and ".SetValue(") or
136- powershell.file.script_block_text:("::AllocHGlobal((" and ("System.Management.Automation.$([" or "System.$([cHAr]" or "[cHaR]([byTe]")) or
137135 powershell.file.script_block_text:("::AllocHGlobal((" and ".SetValue(" and "-replace" and ".NoRMALiZe(")
138136 ) and
139137 not powershell.file.script_block_text : (
You can’t perform that action at this time.
0 commit comments