UtilityFunctions.ps1 Proxy Dll (0403d67d-6227-4ea8-8145-4e72db7da120)
Detects the use of a Microsoft signed script executing a managed DLL with PowerShell.
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
System Script Proxy Execution - T1216 (f6fe9070-7a65-49ea-ae72-76292f42cebe) | Attack Pattern | UtilityFunctions.ps1 Proxy Dll (0403d67d-6227-4ea8-8145-4e72db7da120) | Sigma-Rules | 1 |