Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

BIOC - Powershell Script Based Alert Detection

L3 Networker

We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script.


Lets say if a Powershell script which is being run has certain parameters in the body such as "replace","Download","Invoke-WebRequest" etc...


Is it possible to create a BIOC rule for the content inside in the script?


Thanks in Advance.

Kind Regards
Who Me Too'd this topic