Gzip Archive Decode Via PowerShell

Rule Info

Name
Gzip Archive Decode Via PowerShell
Author
Hieu Tran
Description
Detects attempts of decoding encoded Gzip archives via PowerShell.
Date
2023-03-13 00:00:00
Modified
None
Id
98767d61-b2e8-4d71-b661-e36783ee24c1
Tags
attack.command-and-control attack.t1132.001
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
github-actions[bot]
Merge PR #4700 from @nasbench - Promote older rules status from `experimental` to `test`
2024-02-01
Tessa Georgen
Merge PR #4392 from @tjgeorgen - Update MITRE Tags
2023-08-28
Hieu Tran
feat: new rules related to ZScaler blog - OneNote: A Growing Threat for Malware Distribution (#4111)
2023-03-17