Skip to content

Detect PowerShell w/o PowerShell Execution via RunDLL32 and various other methods #4197

@JulianDroste

Description

@JulianDroste

Description of the Idea of the Rule

I want to propose a rule enabling the detection of PowerShell without using the well-known powershell.exe but rather via rundll32.exe and various other methods. Projects like PowerShx and its predecessor PowerShdll enable this method of PowerShell Execution. Happy to gather feedback from you!

Public References / Example Event Log

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions