LoFP LoFP / as the script block is a blob of text. false positive may occur with scripts that contain the keyword as a reference or simply use it for detection.

Techniques

Sample rules

HackTool - WinPwn Execution - ScriptBlock

Description

Detects scriptblock text keywords indicative of potential usge of the tool WinPwn. A tool for Windows and Active Directory reconnaissance and exploitation.

Detection logic

condition: selection
selection:
  ScriptBlockText|contains:
  - Offline_Winpwn
  - 'WinPwn '
  - WinPwn.exe
  - WinPwn.ps1