ET ATTACK_RESPONSE Nishang Invoke-PowerShellTcp Shell Prompt Outbound
Query · suricata
flow:established,to_server; stream_size:server,<,5; content:"Windows PowerShell running as user"; startswith; fast_pattern; content:"|20|on|20|"; within:258;
flow:established,to_server; stream_size:server,<,5; content:"Windows PowerShell running as user"; startswith; fast_pattern; content:"|20|on|20|"; within:258;
Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.