Sagan critical stable other
[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell
[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell
Detection Logic
alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-POWERSHELL] Windows Defender Restarted via PowerShell"; program:*PowerShell*; event_id:600; content:"HostApplication=powershell"; nocase; content:"restart-service WinDefend"; nocase; reference:url,https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/; classtype:trojan-activity; sid:5015082; rev:1; metadata:deployment Endpoint, created_at 2024_08_13, updated_at 2024_08_13, mitre_tactic_id TA0008, mitre_technique_id T1071;) Field Validations
Loading…
Comments (0)
Loading comments...