diff --git a/Windows Powershell/100535-win_powershell_rules.xml b/Windows Powershell/100535-win_powershell_rules.xml index 7e5eca1..0af6d3c 100644 --- a/Windows Powershell/100535-win_powershell_rules.xml +++ b/Windows Powershell/100535-win_powershell_rules.xml @@ -64,7 +64,7 @@ VERBOSE Powershell script $(win.eventdata.scriptBlockText) Executed - T1087.002> + T1087.002 no_full_log @@ -73,7 +73,7 @@ ^4105$|^4106$ Disregard Powershell Text - T1087.002> + T1087.002 @@ -81,7 +81,7 @@ etc/lists/malicious-powershell Malicious Powershell Command $(win.eventdata.scriptBlockText) Executed - T1087.002> + T1087.002 no_full_log @@ -90,7 +90,7 @@ PSMessageDetails|ErrorCategory_Message|OriginInfo Disregard Powershell Prompt Text - T1087.002> + T1087.002 @@ -98,7 +98,7 @@ ^prompt$ Disregard Powershell Prompt Text - T1087.002> + T1087.002