Detection rules › Equivalence class
eq_0001 — 2 rules with the same canonical form
Members
MITRE ATT&CK coverage
Stages and predicates (per member)
Each member's stage rendered in its own native syntax (verbatim source where the IR captures it; falls back to the synthesised native form for the few stage types whose source segments aren't recoverable).
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 1 esql:from
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 2 esql:where
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 3 esql:eval
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 4 esql:where
Esql.script_block_length > 500Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 5 esql:eval
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 6 esql:eval
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 7 esql:keep
Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion — stage 8 esql:where
Esql.script_block_pattern_count >= 1Potential Dynamic IEX Reconstruction via Environment Variables — stage 9 esql:from
Potential Dynamic IEX Reconstruction via Environment Variables — stage 10 esql:where
Potential Dynamic IEX Reconstruction via Environment Variables — stage 11 esql:eval
Potential Dynamic IEX Reconstruction via Environment Variables — stage 12 esql:where
Esql.script_block_length > 500Potential Dynamic IEX Reconstruction via Environment Variables — stage 13 esql:eval
Potential Dynamic IEX Reconstruction via Environment Variables — stage 14 esql:eval
Potential Dynamic IEX Reconstruction via Environment Variables — stage 15 esql:keep
Potential Dynamic IEX Reconstruction via Environment Variables — stage 16 esql:where
Esql.script_block_pattern_count >= 1Indicators (across all members)
| Field | Kind | Value | Members | Corpus |
|---|---|---|---|---|
Esql.script_block_length | gt | 500 | 2 | 6 |
Esql.script_block_pattern_count | ge | 1 | 2 | 6 |