Sagan critical stable other

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell"; program:*PowerShell*; event_id:600; content:"HostApplication=powershell"; nocase; content:"restart-service WinDefend"; nocase; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; classtype:trojan-activity; sid:5015082; rev:1; metadata:deployment Endpoint, created_at 2024_08_13, updated_at 2024_08_13, mitre_tactic_id TA0008, mitre_technique_id T1071;)

Field Validations

Loading…

Comments (0)

Loading comments...