Search and filter across all detection sources
516 rules
[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [1/2]
[WINDOWS-POWERSHELL] PowerShell Auto Login Enabled, Possible Persistance Attempt [2/2]
[DYNAMIC] PowerShell logs detect via program
[WINDOWS-POWERSHELL] Chrome Login Data Retrieval
Logon Script Registry Key added [splunk-powershell]
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.
[DYNAMIC] Azure Eventhub Windows Powershell Logs Detected
[WINDOWS-POWERSHELL] Access to Brave Login/Cookie Data
[WINDOWS-POWERSHELL] Access to Chrome Login/Cookie Data
[WINDOWS-POWERSHELL] Access to Firefox Login/Cookie Data
[WINDOWS-POWERSHELL] Access to Opera Login/Cookie Data
[WINDOWS-POWERSHELL] Mimikatz Command Line Parameters (sekurlsa::logonpasswords)
[WINDOWS-POWERSHELL] Access to Microsoft Edge Login/Cookie Data
PowerShell Logging Disabled Via Registry Key Tampering
Detects changes to the registry for the currently logged-in user. In order to disable PowerShell module logging, script block logging or transcription and script execution logging
PowerShell Console History Logs Deleted
Detects the deletion of the PowerShell console History logs which may indicate an attempt to destroy forensic evidence
MITRE ATT&CK T1033 Recon Successful Logon Enumeration Powershell CISA Report
Detects the use of powershell to enumerate successful logins on a specific host