HS
Harish Segar
First rule: Wed Mar 22 2017 01:00:00 GMT+0100 (Central European Standard Time)
0rules authored
1sole author
5co-authored
Rule Types
By Severity
critical
0
high
1
medium
3
low
2
informational
0
By Status
stable
0
test
6
experimental
0
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Renamed Powershell Under Powershell Channel
Mon Jun 29 2020 02:00:00 GMT+0200 (Central European Summer Time)
lowDetection
bXOR Operator Usage In PowerShell Command Line - PowerShell Classic
Mon Jun 29 2020 02:00:00 GMT+0200 (Central European Summer Time)
lowThreat Hunt
PowerShell Downgrade Attack - PowerShell
Wed Mar 22 2017 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Suspicious PowerShell Parent Process
Fri Mar 20 2020 01:00:00 GMT+0100 (Central European Standard Time)
highDetection
Suspicious XOR Encoded PowerShell Command
Wed Sep 05 2018 02:00:00 GMT+0200 (Central European Summer Time)
mediumDetection
Potential PowerShell Downgrade Attack
Fri Mar 20 2020 01:00:00 GMT+0100 (Central European Standard Time)
mediumDetection
Browse all 6 rules by Harish Segar
Filter the full rule library to see only their contributions