cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

BIOC - Powershell Script Based Alert Detection

L3 Networker

We know that Cortex has the ability to use AMSI but is any one able to achieve a BIOC rule which can trigger an alert for the content inside the script.

 

Lets say if a Powershell script which is being run has certain parameters in the body such as "replace","Download","Invoke-WebRequest" etc...

 

Is it possible to create a BIOC rule for the content inside in the script?

 

Thanks in Advance.

Kind Regards
KS
Who Me Too'd this topic