

Matched rule: PowerShell _Case_Anom aly date = 1, author = Florian Roth, desc ription = Detects ob fuscated P owerShell hacktools, reference = https:/ /twitter.c om/danielh bohannon/s tatus/9050 9610692476 1088, lice nse = http s://creati vecommons. Multi AV Scanner detection for submitted file Standard Non-Application Layer Protocol 2ĭeobfuscate/Decode Files or Information 1 Found Word or Excel or PowerPoint or XPS Viewer.Found application associated with file extension.Number of analysed new started processes analysed:
