Search and filter across all detection sources
2,126 rules
[WINDOWS-POWERSHELL] Powershell DisableIntrusionPreventionSystem detected
[WINDOWS-POWERSHELL] Powershell DisableRealtimeMonitoring detected
[WINDOWS-POWERSHELL] Powershell DisableScriptScanning detected
[WINDOWS-POWERSHELL] PowerShell Retrieve Users
[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation
[WINDOWS-POWERSHELL] Hoaxshell Uniq Identifier (PowerShell)
[WINDOWS-POWERSHELL] Powershell MAPSReporting Disabled detected
[WINDOWS-POWERSHELL] Powershell Options StrReverse Obfuscation
[WINDOWS-POWERSHELL] Powershell Possible Downgrade Attempt
Alternate PowerShell Hosts - PowerShell Module
Detects alternate PowerShell hosts potentially bypassing detections looking for powershell.exe
[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)
[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell
[WINDOWS-POWERSHELL] Windows Defender Uninstalled via PowerShell
[WINDOWS-POWERSHELL] Windows Firewall Restarted via PowerShell
Suspicious PowerShell Download - Powershell Script
Detects suspicious PowerShell download command
[WINDOWS-POWERSHELL] Powershell created local user [1/3]
[WINDOWS-POWERSHELL] Powershell created local user [2/3]