File tree Expand file tree Collapse file tree 1 file changed +2
-2
lines changed Expand file tree Collapse file tree 1 file changed +2
-2
lines changed Original file line number Diff line number Diff line change 1
- name : Windows Renamed Powershell
1
+ name : Windows Renamed Powershell Execution
2
2
id : c08014de-cc5a-42de-9775-76ecd5b37bbd
3
3
version : 1
4
4
date : ' 2025-05-07'
@@ -19,7 +19,7 @@ search: '| tstats `security_content_summariesonly` count min(_time) as firstTime
19
19
| `drop_dm_object_name(Processes)`
20
20
| `security_content_ctime(firstTime)`
21
21
| `security_content_ctime(lastTime)`
22
- | `windows_renamed_powershell_filter `'
22
+ | `windows_renamed_powershell_execution_filter `'
23
23
how_to_implement : The detection is based on data that originates from Endpoint Detection
24
24
and Response (EDR) agents. These agents are designed to provide security-related
25
25
telemetry from the endpoints where the agent is installed. To implement this search,
You can’t perform that action at this time.
0 commit comments