Sagan high stable other
[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation
[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Powershell StrReverse Obfuscation"; program: *PowerShell*; event_id:400,800,4103,4104; content:"StrReverse
| 28
| "; nocase; content:"llehSrewoP"; nocase; reference:url,bazaar.abuse.ch/download/aa87d136aacebb0496371be929657834d541209ef53695e45dc0acc8b65663a7/; classtype:suspicious-command; sid:5007135; rev:1; metadata:updated_at 2023_10_10, mitre_tactic_id TA0005, mitre_technique_id T1027.010;) Field Validations
Loading…
Comments (0)
Loading comments...