Skip to content

[New Rule] Unusual CommandShell Parent Process#202

Merged
Samirbous merged 14 commits into
mainfrom
Suspicious-Cmd-ParentProcess-Tunning
Sep 28, 2020
Merged

[New Rule] Unusual CommandShell Parent Process#202
Samirbous merged 14 commits into
mainfrom
Suspicious-Cmd-ParentProcess-Tunning

Conversation

@Samirbous
Copy link
Copy Markdown
Contributor

Issues

Resolves #201

Summary

Contributor checklist

@Samirbous Samirbous added v7.10.0 Rule: New Proposal for new rule OS: Windows windows related rules labels Aug 21, 2020
@Samirbous Samirbous self-assigned this Aug 21, 2020
Comment thread rules/windows/execution_command_shell_started_by_unusual_process.toml Outdated
Comment thread rules/windows/execution_command_shell_started_by_unusual_process.toml Outdated
Comment thread rules/windows/execution_command_shell_started_by_unusual_process.toml Outdated
Comment thread rules/windows/execution_command_shell_started_by_unusual_process.toml Outdated
Samirbous and others added 4 commits September 4, 2020 21:21
…ss.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…ss.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…ss.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
…ss.toml

Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>
@Samirbous Samirbous merged commit fc3dcdf into main Sep 28, 2020
@Samirbous Samirbous deleted the Suspicious-Cmd-ParentProcess-Tunning branch September 28, 2020 21:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

OS: Windows windows related rules Rule: New Proposal for new rule v7.10.0

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[New Rule] Unusual Commandshell Parent Process

4 participants