Sagan critical stable other

[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)

[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Possible Hoaxshell attempt (PowerShell Script)"; json_map:"message",".Message"; json_map:"event_id",".EventID"; program:*PowerShell*; event_id:800; content:"-Headers"; content:"Authorization"; content:"Invoke-RestMethod"; nocase; content:"-UseBasicParsing"; content:!"
| 5c
| Microsoft VS Code
| 5c
| "; reference:url,github.com/t3l3machus/hoaxshell; classtype:trojan-activity; sid:5013553; rev:3; metadata:deployment Both,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2023_07_06, updated_at 2026_07_29, mitre_tactic_id TA0002, mitre_technique_id T1059;)

Field Validations

Loading…

Comments (0)

Loading comments...