Techniques
Sample rules
PowerShell Script With File Hostname Resolving Capabilities
- source: sigma
- technicques:
- t1020
Description
Detects PowerShell scripts that have capabilities to read files, loop through them and resolve DNS host entries.
Detection logic
condition: selection
selection:
ScriptBlockText|contains|all:
- 'Get-content '
- foreach
- '[System.Net.Dns]::GetHostEntry'
- Out-File