Powershell script compiling code using CSC.exe, possible malware drop
Description
Powershell script compiling code using CSC.exe, possible malware drop
Query · wazuh
field win.eventdata.image="(?i)\\csc\.exe" AND field win.eventdata.parentCommandLine="(?i)powershell.+ExecutionPolicy\s+bypass"
Rule dependencies
Depends on
-
composes · Wazuh if_group
sysmon_event1856 rules in this analytic story