Skip to content

Commit a589fcf

Browse files
committed
pwshmsix
1 parent 35eda15 commit a589fcf

File tree

2 files changed

+16
-0
lines changed

2 files changed

+16
-0
lines changed
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
author: Michael Haag
2+
id: 3f9b2623-abd5-11eb-926b-120zf0943f11
3+
date: '2023-06-22'
4+
description: PowerShell execution from MSIX packages and WindowsApps directory
5+
environment: attack_range
6+
dataset:
7+
- https://media.githubusercontent.com/media/splunk/attack_data/refs/heads/master/datasets/attack_techniques/T1059.001/msix_powershell/windows-sysmon.log
8+
sourcetypes:
9+
- XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
10+
references:
11+
- https://attack.mitre.org/techniques/T1059/001
12+
- https://redcanary.com/blog/threat-intelligence/msix-installers/
13+
- https://redcanary.com/threat-detection-report/techniques/installer-packages/
Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,3 @@
1+
version https://git-lfs.github.com/spec/v1
2+
oid sha256:3f349b90eead3e2eda89bcc776b5f250f1ece2bd1a2c9d128ca79ad087d72e93
3+
size 7346

0 commit comments

Comments
 (0)