Rule Library
Sigma Rules
3 rules found for "Lee Holmes"
3,731Total
3,132Detection
457Emerging
139Hunting
Detectionmediumtest
PowerShell Downgrade Attack - PowerShell
Detects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
WindowsPowerShell Classic
Florian Roth (Nextron Systems)+2Wed Mar 22windows
Detectionhightest
Malicious Base64 Encoded PowerShell Keywords in Command Lines
Detects base64 encoded strings used in hidden malicious PowerShell command lines
WindowsProcess Creation
John LambertWed Jan 16windows
Detectionmediumtest
Potential PowerShell Downgrade Attack
Detects PowerShell downgrade attack by comparing the host versions with the actually used engine version 2.0
WindowsProcess Creation
Harish SegarFri Mar 20windows