Detection rules › By event
PowerShell event 400
Sigma (9)
- Delete Volume Shadow Copies Via WMI With PowerShell
- Netcat The Powershell Version
- Nslookup PowerShell Download Cradle
- PowerShell Called from an Executable Version Mismatch
- PowerShell Downgrade Attack - PowerShell
- Remote PowerShell Session (PS Classic)
- Renamed Powershell Under Powershell Channel
- Suspicious PowerShell Download
- Use Get-NetTCPConnection