2610490 FP's

This rule needs some tuning…falsing fairly often.
[1:2610490:2] TGI HUNT PowerShell Execution String Base64 Encoded New-Object (ctT2J) [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1]

Hi James, that one is from my (non ET) rules, fixed here

Thanks for the feedback!

Well hey there Travis, long time no chat :slight_smile: Thanks for the fix!

1 Like