04-21-2022 04:13 PM
We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script.
Lets say if a Powershell script which is being run has certain parameters in the body such as "replace","Download","Invoke-WebRequest" etc...
Is it possible to create a BIOC rule for the content inside in the script?
Thanks in Advance.