Title:Potential Persistence Via Powershell Search Order Hijacking - Task Status:test Description:Detects suspicious powershell execution via a schedule task where the command ends with an suspicious flags to hide the powershell instance instead of executeing scripts or commands. This could be a sign of persistence via PowerShell "Get-Variable" technique as seen being used in Colibri Loader References: -https://blog.malwarebytes.com/threat-intelligence/2022/04/colibri-loader-combines-task-scheduler-and-powershell-in-clever-persistence-technique/ Author: pH-T (Nextron Systems), Florian Roth (Nextron Systems) Date: 2022-04-08 modified:2023-02-03 Tags: