Detection rules › By event
Microsoft-Windows-PowerShell Event ID 4104
Sigma (218)
- AADInternals PowerShell Cmdlets Execution - PsScript
- Abuse of Service Permissions to Hide Services Via Set-Service - PS
- Access to Browser Login Data
- Active Directory Computers Enumeration With Get-AdComputer
- Active Directory Forest PowerShell class called from a non administrative host
- Active Directory Group Enumeration With Get-AdGroup
- AD Groups Or Users Enumeration Using PowerShell - ScriptBlock
- Add Windows Capability Via PowerShell Script
- AMSI Bypass Pattern Assembly GetType
- Automated Collection Bookmarks Using Get-ChildItem PowerShell
- Automated Collection Command PowerShell
- BitLocker server feature activation (PowerShell)
- BITS payload downloaded via PowerShell
- Certificate Exported Via PowerShell - ScriptBlock
- Change PowerShell Policies to an Insecure Level - PowerShell
- Change User Agents with WebRequest
- Clear PowerShell History - PowerShell
- Clearing Windows Console History
- Code Executed Via Office Add-in XLL File
- Compress-Archive Cmdlet Execution
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
- Create Volume Shadow Copy with Powershell
- DCOM lateral movement (via MMC20)
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script
- Detected Windows Software Discovery - PowerShell
- DirectorySearcher Powershell Exploitation
- Disable of ETW Trace - Powershell
- Disable Powershell Command History
- Disable-WindowsOptionalFeature Command PowerShell
- DMSA Link Attributes Modified
- DMSA Service Account Created in Specific OUs - PowerShell
- Domain group membership change
- DoT (DNS over TLS) activation (PowerShell)
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock
- DSRM password changed (Reg via PowerShell)
- Dump Credentials from Windows Credential Manager With PowerShell
- Enable Windows Remote Management
- Encoded PowerShell payload deployed (PowerShell)
- Enumerate Credentials from Windows Credential Manager With PowerShell
- Event log clear attempt (PowerShell)
- Event log cleared using Diagnostics (via PowerShell)
- Exchange transport agent installation artifacts (PowerShell)
- Execute Invoke-command on Remote Host
- Extracting Information with PowerShell
- Firewall configuration enumerated (PowerShell)
- Firewall deactivation (PowerShell)
- Get-ADUser Enumeration Using UserAccountControl Flags
- Group discovery (PowerShell)
- HackTool - Rubeus Execution - ScriptBlock
- HackTool - WinPwn Execution - ScriptBlock
- Import PowerShell Modules From Suspicious Directories
- Inbox Rules Creation Or Update Activity Via ExchangePowerShell Cmdlet
- Invoke-Obfuscation CLIP+ Launcher - PowerShell
- Invoke-Obfuscation COMPRESS OBFUSCATION - PowerShell
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell
- Invoke-Obfuscation RUNDLL LAUNCHER - PowerShell
- Invoke-Obfuscation STDIN+ Launcher - Powershell
- Invoke-Obfuscation VAR+ Launcher - PowerShell
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell
- Invoke-Obfuscation Via Stdin - Powershell
- Invoke-Obfuscation Via Use Clip - Powershell
- Invoke-Obfuscation Via Use MSHTA - PowerShell
- Invoke-Obfuscation Via Use Rundll32 - PowerShell
- Lace Tempest PowerShell Evidence Eraser
- Lace Tempest PowerShell Launcher
- Live Memory Dump Using Powershell
- Local group membership change
- LSASS credential dump with LSASSY (PowerShell)
- Mail Forwarding/Redirecting Activity Via ExchangePowerShell Cmdlet
- Malicious Nishang PowerShell Commandlets
- Malicious PowerShell Commandlets - ScriptBlock
- Malicious PowerShell Keywords
- Malicious ShellIntel PowerShell Commandlets
- Manipulation of User Computer or Group Security Principals Across AD
- Microsoft Defender critical security components disabled (PowerShell)
- Microsoft Defender default action changed to allow any threat (PowerShell)
- Microsoft Defender security components disabled (PowerShell)
- Microsoft Defender threat exclusion added (PowerShell)
- Modify Group Policy Settings - ScriptBlockLogging
- New Windows Firewall Rule Added Via New-NetFirewallRule Cmdlet - ScriptBlock
- NTFS Alternate Data Stream
- OpenSSH native server feature installation
- OpenSSH server firewall configuration on Windows (PowerShell)
- OpenSSH service activation on Windows
- Password Policy Discovery With Get-AdDefaultDomainPasswordPolicy
- Payload downloaded via PowerShell
- PipeShell exfiltration over named pipes
- Potential Active Directory Enumeration Using AD Module - PsScript
- Potential AMSI Bypass Script Using NULL Bits
- Potential APT FIN7 POWERHOLD Execution
- Potential COM Objects Download Cradles Usage - PS Script
- Potential Data Exfiltration Over SMTP Via Send-MailMessage Cmdlet
- Potential Data Exfiltration Via Audio File
- Potential In-Memory Execution Using Reflection.Assembly
- Potential Invoke-Mimikatz PowerShell Script
- Potential Keylogger Activity
- Potential Packet Capture Activity Via Start-NetEventSession - ScriptBlock
- Potential Persistence Via PowerShell User Profile Using Add-Content
- Potential Persistence Via Security Descriptors - ScriptBlock
- Potential PowerShell Obfuscation Using Alias Cmdlets
- Potential PowerShell Obfuscation Using Character Join
- Potential POWERTRASH Script Execution
- Potential Registry Reconnaissance Via PowerShell Script
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock
- Potential Suspicious PowerShell Keywords
- Potential Suspicious Windows Feature Enabled
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
- Potential WinAPI Calls Via PowerShell Scripts
- Potentially Suspicious Call To Win32_NTEventlogFile Class - PSScript
- Powershell Add Name Resolution Policy Table Rule
- PowerShell ADRecon Execution
- PowerShell Create Local User
- Powershell Create Scheduled Task
- PowerShell Credential Prompt
- PowerShell Deleted Mounted Share
- Powershell Detect Virtualization Environment
- Powershell Directory Enumeration
- Powershell DNSExfiltration
- Powershell Execute Batch Script
- PowerShell Get-Process LSASS in ScriptBlock
- PowerShell Hotfix Enumeration
- PowerShell ICMP Exfiltration
- Powershell Install a DLL in System Directory
- Powershell Keylogging
- Powershell Local Email Collection
- Powershell LocalAccount Manipulation
- Powershell MsXml COM Object
- PowerShell PSAttack
- PowerShell Remote Session Creation
- PowerShell Script Change Permission Via Set-Acl - PsScript
- PowerShell Script With File Hostname Resolving Capabilities
- PowerShell Script With File Upload Capabilities
- Powershell Sensitive File Discovery
- PowerShell Set-Acl On Windows Folder - PsScript
- PowerShell ShellCode
- Powershell Store File In Alternate Data Stream
- Powershell Suspicious Win32_PnPEntity
- Powershell Timestomp
- Powershell Token Obfuscation - Powershell
- PowerShell Web Access Installation - PsScript
- Powershell WMI Persistence
- PowerShell WMI Win32_Product Install MSI
- PowerShell Write-EventLog Usage
- Powershell XML Execute Command
- PowerView PowerShell Cmdlets - ScriptBlock
- Print spooler privilege escalation via printer added (CVE-2020-1048)
- PSAsyncShell - Asynchronous TCP Reverse Shell
- Recon Information for Export with PowerShell
- Registry Modification Attempt Via VBScript - PowerShell
- Registry-Free Process Scope COR_PROFILER
- Remove Account From Domain Admin Group
- Replace Desktop Wallpaper by Powershell
- Root Certificate Installed - PowerShell
- Security Software Discovery Via Powershell Script
- Service abuse with backdoored "command failure" (Reg via PowerShell)
- Service abuse with malicious ImagePath (Reg via PowerShell)
- Service creation (PowerShell)
- Service permissions hijacked for privileges abuse (PowerShell)
- Service permissions hijacked for privileges abuse (Reg via PowerShell)
- Service Registry Permissions Weakness Check
- Silence.EDA Detection
- SMB over QUIC Via PowerShell Script
- Suspicious Connection to Remote Account
- Suspicious Eventlog Clear
- Suspicious FromBase64String Usage On Gzip Archive - Ps Script
- Suspicious Get Information for SMB Share
- Suspicious Get Local Groups Information - PowerShell
- Suspicious Get-ADReplAccount
- Suspicious GetTypeFromCLSID ShellExecute
- Suspicious GPO Discovery With Get-GPO
- Suspicious Hyper-V Cmdlets
- Suspicious Invoke-Item From Mount-DiskImage
- Suspicious IO.FileStream
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock
- Suspicious Mount-DiskImage
- Suspicious New-PSDrive to Admin Share
- Suspicious PowerShell Download - Powershell Script
- Suspicious PowerShell Get Current User
- Suspicious PowerShell Invocations - Generic
- Suspicious PowerShell Invocations - Specific
- Suspicious PowerShell Mailbox Export to Share - PS
- Suspicious PowerShell WindowStyle Option
- Suspicious Process Discovery With Get-Process
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
- Suspicious SPN enumeration previous to Kerberoasting attack (PowerShell)
- Suspicious SSL Connection
- Suspicious Start-Process PassThru
- Suspicious TCP Tunnel Via PowerShell Script
- Suspicious Unblock-File
- Suspicious X509Enrollment - Ps Script
- SyncAppvPublishingServer Execution to Bypass Powershell Restriction
- System time changed (PowerShell)
- Tamper Windows Defender - ScriptBlockLogging
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging
- Testing Usage of Uncommonly Used Port
- Troubleshooting Pack Cmdlet Execution
- Unsigned AppX Installation Attempt Using Add-AppxPackage - PsScript
- Usage Of Web Request Commands And Cmdlets - ScriptBlock
- Use Of Remove-Item to Delete File - ScriptBlock
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
- Vault credentials manager accessed
- Veeam Backup Servers Credential Dumping Script Execution
- Vice Society directory crawling script for data exfiltration (via ps_script)
- VSS backup deletion via WMI (Powershell)
- Webserver IIS module installed (PowerShell)
- Webserver IIS module installed via GAC manipulation (PowerShell)
- WinAPI Function Calls Via PowerShell Scripts
- WinAPI Library Calls Via PowerShell Scripts
- Windows Defender Exclusions Added - PowerShell
- Windows Firewall Profile Disabled
- Windows Mail App Mailbox Access Via PowerShell Script
- Windows Screen Capture with CopyFromScreen
- Windows Subsystem for Linux (WSL) installation (PowerShell)
- Winlogon Helper DLL
- WMI registration (PowerShell)
- WMIC Unquoted Services Path Lookup - PowerShell
- WMImplant Hack Tool
- Zip A Folder With PowerShell For Staging In Temp - PowerShell Script
Elastic (13)
- Dynamic IEX Reconstruction via Method String Access
- Potential Dynamic IEX Reconstruction via Environment Variables
- Potential PowerShell Obfuscation via Backtick-Escaped Variable Expansion
- Potential PowerShell Obfuscation via Character Array Reconstruction
- Potential PowerShell Obfuscation via Concatenated Dynamic Command Invocation
- Potential PowerShell Obfuscation via High Numeric Character Proportion
- Potential PowerShell Obfuscation via High Special Character Proportion
- Potential PowerShell Obfuscation via Invalid Escape Sequences
- Potential PowerShell Obfuscation via Reverse Keywords
- Potential PowerShell Obfuscation via Special Character Overuse
- Potential PowerShell Obfuscation via String Concatenation
- Potential PowerShell Obfuscation via String Reordering
- PowerShell Obfuscation via Negative Index String Reversal
Splunk (279)
- Access Common Package Config file (PowerShell)
- Account Password Changed from Command Line - Windows (PowerShell)
- Adfind Commands (PowerShell)
- Adfind Execution (PowerShell)
- AdsiSearcher Account Discovery
- Allow Inbound Traffic In Firewall Rule
- Application Discovery - Windows (PowerShell)
- ATBroker.exe Execution (PowerShell)
- Attempted Veeam Database Credential Dump (PowerShell)
- AutoHotkey Execution (PowerShell)
- AutoIt Execution (PowerShell)
- BITSadmin Execution (PowerShell)
- Browser Started with Remote Debugging - Windows (PowerShell)
- Bypass or Unrestricted PowerShell Execution (PowerShell)
- Certutil File Download (PowerShell)
- Certutil Obfuscate_Encode Files (PowerShell)
- CMD execution with _c (PowerShell)
- Command Line Homoglyphs - Windows (PowerShell)
- Command Line lsass request (PowerShell)
- Common Active Directory Commands (PowerShell)
- Common Exchange Recon cmdlets (PowerShell)
- Common Reconnaissance Commands (PowerShell)
- ComputerDefaults UAC Bypass (PowerShell)
- ConsentPromptBehaviorAdmin Registry Value Modified (PowerShell)
- Create_Modify Schtasks (PowerShell)
- CSVDE Export Active Directory (PowerShell)
- Data Staged to File (PowerShell)
- Delete ShadowCopy With PowerShell
- Detect Certify With PowerShell Script Block Logging
- Detect Copy of ShadowCopy with Script Block Logging
- Detect Empire with PowerShell Script Block Logging
- Detect Mimikatz With PowerShell Script Block Logging
- Disabled Kerberos Pre-Authentication Discovery With Get-ADUser
- Disabled Kerberos Pre-Authentication Discovery With PowerView
- Disabled Pre-Authentication Accounts Discovery - PowerShell (PowerShell)
- DLL Called with RS32 (PowerShell)
- DLL Called with Uncommon Function (PowerShell)
- DLL Concatenation (PowerShell)
- DLL Execution from Uncommon Process (PowerShell)
- DLLRegisterServer Called from Command Line (PowerShell)
- Domain Controller Enumeration via nltest (PowerShell)
- Domain Group Discovery with Adsisearcher
- Domain Trust Discovery Commands - Windows (PowerShell)
- Dump File Identified (PowerShell)
- Elevated Group Discovery with PowerView
- EnableLUA Registry Value Modified (PowerShell)
- Encoded Powershell Command (PowerShell)
- Esentutl Execution (PowerShell)
- ETW Trace Provider Modified - PowerShell (PowerShell)
- Event Logs Queried for RDP Sessions (PowerShell)
- Exchange New Export Request (PowerShell)
- Exchange PowerShell Module Usage
- Executable Create Script Process (PowerShell)
- Executable Process from Suspicious Folder (PowerShell)
- Exfiltration via curl.exe - Windows (PowerShell)
- Expand.exe Execution (PowerShell)
- File and Directory Discovery Output to File - Windows (PowerShell)
- File_Folder Hidden - Windows (PowerShell)
- Get ADDefaultDomainPasswordPolicy with Powershell Script Block
- Get ADUser with PowerShell Script Block
- Get ADUserResultantPasswordPolicy with Powershell Script Block
- Get DomainPolicy with Powershell Script Block
- Get DomainUser with PowerShell Script Block
- Get WMIObject Group Discovery with Script Block Logging
- Get-DomainTrust with PowerShell Script Block
- Get-ForestTrust with PowerShell Script Block
- GetAdComputer with PowerShell Script Block
- GetAdGroup with PowerShell Script Block
- GetCurrent User with PowerShell Script Block
- GetDomainComputer with PowerShell Script Block
- GetDomainController with PowerShell Script Block
- GetDomainGroup with PowerShell Script Block
- GetLocalUser with PowerShell Script Block
- GetNetTcpconnection with PowerShell Script Block
- GetWmiObject Ds Computer with PowerShell Script Block
- GetWmiObject Ds Group with PowerShell Script Block
- GetWmiObject DS User with PowerShell Script Block
- GetWmiObject User Account with PowerShell Script Block
- Git Clone Repository (PowerShell)
- Go Run Execution (PowerShell)
- Group Policy Editor Execution (PowerShell)
- hh.exe Execution (PowerShell)
- hh.exe Remote File Execution (PowerShell)
- High Entropy Powershell (PowerShell)
- HTTP_HTTPS Default Security Zone Modified to Local Machine (PowerShell)
- Impacket atexec.py Execution (PowerShell)
- Interactive Session on Remote Endpoint with PowerShell
- Invoke-DCOM.ps1 - PowerShell (PowerShell)
- Invoke-Expression Command (PowerShell)
- Invoke-WebRequest Command (PowerShell)
- ISO Image Mounted - Windows (PowerShell)
- Kerberos Pre-Authentication Flag Disabled with PowerShell
- Known Process Injection Commands (PowerShell)
- LocalAccountTokenFilterPolicy Registry Value Modified (PowerShell)
- Locate Credentials (PowerShell)
- Logon Script Registry Key added (PowerShell)
- LSA Authentication Packages Registry Key Modified (PowerShell)
- Mailsniper Invoke functions
- masscan Execution - Windows (PowerShell)
- Modify Exchange Access Settings (PowerShell)
- Modify Windows Defender (PowerShell)
- mshta.exe File Download (PowerShell)
- MSI Installation via Appcert (PowerShell)
- Native Archive Commands (PowerShell)
- Network Share Connection Removal (PowerShell)
- New AutoRun Registry Key (PowerShell)
- ngen.exe File Download (PowerShell)
- ngrok Execution - Windows (PowerShell)
- NMAP Execution (PowerShell)
- Non-MSIExec .msi Installation (PowerShell)
- ntds.dit Command Line (PowerShell)
- Output to File (PowerShell)
- Package installation (PowerShell)
- Permission Groups Discovery: Domain Groups (PowerShell)
- Permission Groups Discovery: Local Groups (PowerShell)
- Permissions Replaced by icacls - Windows (PowerShell)
- Possible Credential Dumping via Windows Network Providers (PowerShell)
- Potential AutoHotkey .ahk Execution (PowerShell)
- Potential Cryptomining Commands (PowerShell)
- Potential fodhelper UAC Bypass Attempt (PowerShell)
- Potential LSA password filter (PowerShell)
- Potential Proxy Malware via AutoRun Key (PowerShell)
- Potential Sysinternals Tool Execution (PowerShell)
- Potential Target Discovery via PowerShell Event Log Queries (PowerShell)
- PowerShell 4104 Hunting
- PowerShell Clipboard Access (PowerShell)
- Powershell COM Hijacking InprocServer32 Modification
- PowerShell CreateDecryptor (PowerShell)
- Powershell Creating Thread Mutex
- Powershell DLL_EXE Injection (PowerShell)
- PowerShell Domain Enumeration
- PowerShell Downgrade (PowerShell)
- PowerShell Download Activity (PowerShell)
- PowerShell DownloadFile_DownloadString (PowerShell)
- PowerShell Enable PowerShell Remoting
- Powershell Enable SMB1Protocol Feature
- PowerShell Environment Variable Execution
- Powershell Execute COM Object
- Powershell Fileless Process Injection via GetProcAddress
- Powershell Fileless Script Contains Base64 Encoded Content
- Powershell Get LocalGroup Discovery with Script Block Logging
- PowerShell Hidden Window (PowerShell)
- PowerShell Invoke CIMMethod CIMSession
- PowerShell Invoke WmiExec Usage
- Powershell Load Module in Meterpreter
- PowerShell Loading DotNET into Memory via Reflection
- PowerShell Modifying Registry Values (PowerShell)
- PowerShell PInvoke Process Injection API Chain
- Powershell Processing Stream Of Data
- Powershell Remote Services Add TrustedHost
- Powershell Remove Windows Defender Directory
- PowerShell Script Block With URL Chain
- PowerShell Start or Stop Service
- Powershell Using memory As Backing Store
- PowerShell WebRequest Using Memory Stream
- Powershell Windows Defender Exclusion Commands
- PowerShell XML Retrieval (PowerShell)
- PowerView_SharpView Commands (PowerShell)
- PromptOnSecureDesktop Registry Value Modified (PowerShell)
- ProtocolHandler.exe File Download (PowerShell)
- Proxy Execution via Appcert (PowerShell)
- PuTTY Secure Copy Client Execution (PowerShell)
- QEMU Network Tunneling - Windows (PowerShell)
- Query Registry (PowerShell)
- Rclone Execution (PowerShell)
- RDP Enabled (PowerShell)
- RdrLeakDiag.exe Memory Dump (PowerShell)
- Read-Only Attribute Removed - Windows (PowerShell)
- Recon AVProduct Through Pwh or WMI
- Recon Using WMI Class
- Registry Entry Created - PowerShell (PowerShell)
- regsvr32 Execution (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote .msi Installation (PowerShell)
- Remote Admin Tools (PowerShell)
- Remote Process Instantiation via DCOM and PowerShell Script Block
- Remote Process Instantiation via WinRM and PowerShell Script Block
- Remote Process Instantiation via WMI and PowerShell Script Block
- Remote Share Directory Listing - Windows (PowerShell)
- Remote System Discovery with Adsisearcher
- Remote WMIC Query (PowerShell)
- Rubeus Commands (PowerShell)
- Rundll32 Command Line (PowerShell)
- Rundll32 Suspicious Command Line (PowerShell)
- rundll32.exe Executing DLL from Non-standard Directory (PowerShell)
- Scheduled Task with Potential SSH Tunnel - Windows (PowerShell)
- Security Software Discovery via Findstr.exe (PowerShell)
- Security Software Discovery via WMI (PowerShell)
- Service Stop Commands (PowerShell)
- ServicePrincipalNames Discovery with PowerShell
- SharpHound Keywords (PowerShell)
- Shortcut Created in Startup Folder - Windows (PowerShell)
- Sliver C2 Implant Activity Pattern (PowerShell)
- Startup Folder Location Modified - Windows (PowerShell)
- Stored Credentials from Web Browsers - Windows (PowerShell)
- Suspicious DLLhost Execution (PowerShell)
- Suspicious ntds.dit Commands (PowerShell)
- Suspicious PowerShell Clipboard Activity (PowerShell)
- Suspicious PowerShell Parameter Substring (PowerShell)
- Suspicious reCAPTCHA Command Line (PowerShell)
- Suspicious Registry Key Created (PowerShell)
- Symbolic OR Hard File Link Created (PowerShell)
- System Information Discovery - Windows (PowerShell)
- System Network Connections Discovery - Windows (PowerShell)
- System Owner_User Discovery - Windows (PowerShell)
- Timestamp Manipulation (PowerShell)
- Tunneling Process Created (PowerShell)
- Unloading AMSI via Reflection
- User Discovery via Environment Variables - PowerShell (PowerShell)
- User Discovery With Env Vars PowerShell Script Block
- User_Domain Enumeration Tool - Windows (PowerShell)
- Utility Archive Data (PowerShell)
- Visio.exe File Download (PowerShell)
- WDigest Forced Credential Caching (PowerShell)
- Windows - Service Stop (PowerShell)
- Windows Account Discovery for None Disable User Account
- Windows Account Discovery for Sam Account Name
- Windows Account Discovery With NetUser PreauthNotRequire
- Windows Archive Collected Data via Powershell
- Windows Azure PowerShell Module Installation Via PowerShell Script
- Windows ClipBoard Data via Get-ClipBoard
- Windows Cobalt Strike PowerShell Loader
- Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
- Windows Copy Files (PowerShell)
- Windows Default Cobalt Strike PowerShell Beacon
- Windows Defender Disabled Detection (PowerShell)
- Windows Domain Account Discovery Via Get-NetComputer
- Windows Enable PowerShell Web Access
- Windows ESX Admins Group Creation via PowerShell
- Windows Exfiltration Over C2 Via Invoke RestMethod
- Windows Exfiltration Over C2 Via Powershell UploadString
- Windows File Share Discovery With Powerview
- Windows Find Domain Organizational Units with GetDomainOU
- Windows Find Interesting ACL with FindInterestingDomainAcl
- Windows Firewall Disabled (PowerShell)
- Windows Firewall Rule Creation (PowerShell)
- Windows Forest Discovery with GetForestDomain
- Windows FTP Exfiltration (PowerShell)
- Windows Gather Victim Host Information Camera
- Windows Get Local Admin with FindLocalAdminAccess
- Windows Get-AdComputer Unconstrained Delegation Discovery
- Windows LAPS Password Gathering Via PowerShell Script
- Windows Level RMM PowerShell Script Installer
- Windows Linked Policies In ADSI Discovery
- Windows PowerShell Add Module to Global Assembly Cache
- Windows Powershell Cryptography Namespace
- Windows PowerShell Disable HTTP Logging
- Windows PowerShell Export Certificate
- Windows PowerShell Export PfxCertificate
- Windows PowerShell Get CIMInstance Remote Computer
- Windows Powershell History File Deletion
- Windows PowerShell IIS Components WebGlobalModule Usage
- Windows Powershell Import Applocker Policy
- Windows PowerShell Invoke-RestMethod IP Information Collection
- Windows PowerShell Invoke-Sqlcmd Execution
- Windows Powershell Logoff User via Quser
- Windows PowerShell MSIX Package Installation
- Windows PowerShell ScheduleTask
- Windows PowerShell Script Block With Malicious String
- Windows PowerShell Script TabExpansion Direct Call
- Windows PowerShell WMI Win32 ScheduledJob
- Windows PowerSploit GPP Discovery
- Windows PowerView AD Access Control List Enumeration
- Windows PowerView Constrained Delegation Discovery
- Windows PowerView Kerberos Service Ticket Request
- Windows PowerView SPN Discovery
- Windows PowerView Unconstrained Delegation Discovery
- Windows Process Copied from System Folder (PowerShell)
- Windows Root Domain linked policies Discovery
- Windows Screen Capture Via Powershell
- Windows Service Started (PowerShell)
- Windows Software Discovery Via PowerShell
- Windows WinPEAS PowerShell Script Execution
- WinLogon Registry Key Modified (PowerShell)
- WinRM Tools (PowerShell)
- WMI Recon Running Process Or Services
- WMIC Host Reconniassance (PowerShell)
- Wow6432Node Classes Autorun Keys Modification (PowerShell)
- Wscript_Cscript Execution (PowerShell)