This rule needs some tuning…falsing fairly often.
[1:2610490:2] TGI HUNT PowerShell Execution String Base64 Encoded New-Object (ctT2J) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1]
Hi James, that one is from my (non ET) rules, fixed here
Thanks for the feedback!
Well hey there Travis, long time no chat Thanks for the fix!
1 Like