Skip to content

Commit

Permalink
Update defense_evasion_posh_assembly_load.toml
Browse files Browse the repository at this point in the history
  • Loading branch information
Samirbous authored Sep 30, 2024
1 parent ef4e433 commit 188a7ef
Showing 1 changed file with 5 additions and 2 deletions.
7 changes: 5 additions & 2 deletions rules/windows/defense_evasion_posh_assembly_load.toml
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ integration = ["windows"]
maturity = "production"
min_stack_comments = "KQL handles backslash and ? characters differently in 8.12+."
min_stack_version = "8.12.0"
updated_date = "2024/07/17"
updated_date = "2024/09/30"

[transform]
[[transform.osquery]]
Expand Down Expand Up @@ -144,7 +144,10 @@ event.category:process and host.os.type:windows and
) and
not powershell.file.script_block_text : (
"Microsoft.PowerShell.Workflow.ServiceCore" and "ExtractPluginProperties([string]$pluginDir"
) and
) and
not powershell.file.script_block_text : ("reflection.assembly]::Load('System." or "LoadWithPartialName('Microsoft." or "::Load(\"Microsoft." or "Microsoft.Build.Utilities.Core.dll") and
not user.id : "S-1-5-18"
'''

Expand Down

0 comments on commit 188a7ef

Please sign in to comment.