Gzip Archive Decode Via PowerShell

Rule Info

Name
Gzip Archive Decode Via PowerShell
Author
Hieu Tran
Description
Detects attempts of decoding encoded Gzip archives via PowerShell.
Date
2023-03-13 00:00:00
Modified
None
Id
98767d61-b2e8-4d71-b661-e36783ee24c1
Tags
attack.command_and_control attack.t1132.001 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #4700 from @nasbench - Promote older rules status from `experimental` to `test`
2024-02-01
Tessa Georgen
Merge PR #4392 from @tjgeorgen - Update MITRE Tags
2023-08-28
Hieu Tran
feat: new rules related to ZScaler blog - OneNote: A Growing Threat for Malware Distribution (#4111)
2023-03-17