Title:Renamed Powershell Under Powershell Channel Status:test Description:Detects a renamed Powershell execution, which is a common technique used to circumvent security controls and bypass detection logic that's dependent on process names and process paths.
References: -https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse Author: Harish Segar, frack113 Date: 2020-06-29 modified:2025-01-20 Tags:
filter_main_host_application_null: Data|re:
'HostId=[a-zA-Z0-9-]{36}\s+EngineVersion=' condition:selection and not 1 of filter_main_* Falsepositives:
-Unknown Level:low