False Detections with Invoke-Obfuscation and Null Bytes #4875
Labels
False-Positive
Issue reporting a false positive with one of the rules
Work In Progress
Some changes are needed
Rule UUID
f3a98ce4-6164-4dd4-867c-4d83de7eca51
Example EventLog
I found this off virus total lol
Description
Script Block is
False code detected is:
Similar code it's meant to detect:
It's looking for obfuscating text but mistaking null bytes as obfuscated text.
The text was updated successfully, but these errors were encountered: