This rule needs some tuning…falsing fairly often.
[1:2610490:2] TGI HUNT PowerShell Execution String Base64 Encoded New-Object (ctT2J) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1]
Well hey there Travis, long time no chat Thanks for the fix!
1 Like