Custom File Open Handler Executes PowerShell (7530b96f-ad8e-431d-a04d-ac85cc461fdc)
Detects the abuse of custom file open handler, executing powershell
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Indirect Command Execution - T1202 (3b0e52ce-517a-4614-a523-1bd5deef6c5e) | Attack Pattern | Custom File Open Handler Executes PowerShell (7530b96f-ad8e-431d-a04d-ac85cc461fdc) | Sigma-Rules | 1 |