Invoke_OSiRis
Description
Osiris Device Guard Bypass - file Invoke-OSiRis.ps1
Query · yara
strings:
$x1 = "$null = Iwmi Win32_Process -EnableA -Impers 3 -AuthenPacketprivacy -Name Create -Arg $ObfusK -Computer $Target" ascii wide
$x3 = "-Arg@{Name=$VarName;VariableValue=$OSiRis;UserName=$env:Username}" ascii wide
$x4 = "Device Guard Bypass Command Execution" ascii wide
condition:
filesize < 8MB
and 1 of them