1 rule found for "HieuTT35"
Detects the creation or modification of a powershell profile which could indicate suspicious activity as the profile can be used as a mean of persistence