
Rule Info
Name
Powershell Executed From Headless ConHost Process
Author
Matt Anderson (Huntress)
Description
Detects the use of powershell commands from headless ConHost window.
The "--headless" flag hides the windows from the user upon execution.
Reference
Date
2024-07-23 00:00:00
Modified
None
Id
056c7317-9a09-4bd4-9067-d051312752ea
Tags
attack.defense-evasion attack.t1059.001 attack.t1059.003
Type
Community Rule
Link to Public Repo