Potential Process Execution Proxy Via CL_Invocation.ps1 (a0459f02-ac51-4c09-b511-b8c9203fc429)
Detects calls to "SyncInvoke" that is part of the "CL_Invocation.ps1" script to proxy execution using "System.Diagnostics.Process"
Cluster A | Galaxy A | Cluster B | Galaxy B | Level |
---|---|---|---|---|
Potential Process Execution Proxy Via CL_Invocation.ps1 (a0459f02-ac51-4c09-b511-b8c9203fc429) | Sigma-Rules | System Script Proxy Execution - T1216 (f6fe9070-7a65-49ea-ae72-76292f42cebe) | Attack Pattern | 1 |