Skip to content

Instantly share code, notes, and snippets.

@MHaggis
Last active October 27, 2020 16:06
Show Gist options
  • Save MHaggis/bb504cf67674f388ccd3919661508b6f to your computer and use it in GitHub Desktop.
Save MHaggis/bb504cf67674f388ccd3919661508b6f to your computer and use it in GitHub Desktop.
Tune as you see fit for your environment
{
"Powershell": {
"process_name": ["powershell.exe"]
},
"PSExec": {
"process_name": ["psexec*.exe",
"psexesvc.exe"]
},
"at": {
"process_name": ["at.exe"]
},
"wsl": {
"process_name": ["wsl.exe"]
},
"ntdsutil": {
"process_name": ["ntdsutil.exe"]
},
"Microsoft.Workflow.Compiler.exe": {
"process_name": ["Microsoft.Workflow.Compiler.exe"]
},
"remcom": {
"process_name": ["remcom.exe"]
},
"nltest": {
"process_name": ["nltest.exe"]
},
"paexec.exe": {
"process_name": ["paexec.exe"]
},
"Scheduled Tasks": {
"process_name": ["schtasks.exe"]
},
"netsh": {
"process_name": ["netsh.exe"]
},
"net": {
"process_name": ["net.exe"]
},
"Vssadmin": {
"process_name": ["vssadmin.exe"]
},
"Utilman": {
"process_name": ["utilman.exe"]
},
"wmic": {
"process_name": ["wmic.exe"]
},
"mshta": {
"process_name": ["mshta.exe"]
},
"wscript": {
"process_name": ["wscript.exe"]
},
"cscript": {
"process_name": ["cscript.exe"]
},
"cmd": {
"process_name": ["cmd.exe"]
},
"whoami": {
"process_name": ["whoami.exe"]
},
"mmc": {
"process_name": ["mmc.exe"]
},
"systeminfo": {
"process_name": ["systeminfo.exe"]
},
"csvde": {
"process_name": ["csvde.exe"]
},
"installutil": {
"process_name": ["installutil.exe"]
},
"msbuild": {
"process_name": ["msbuild.exe"]
},
"quser": {
"process_name": ["quser.exe"]
},
"qwinsta": {
"process_name": ["qwinsta.exe"]
},
"bitsadmin": {
"process_name": ["bitsadmin.exe"]
},
"certutil": {
"process_name": ["certutil.exe"]
},
"regasm": {
"process_name": ["regasm.exe"]
},
"regsvr32": {
"process_name": ["regsvr32.exe"]
},
"rundll32": {
"process_name": ["rundll32.exe"]
},
"Regsvcs": {
"process_name": ["regsvcs.exe"]
},
"waitfor": {
"process_name": ["waitfor.exe"]
},
"rpcping": {
"process_name": ["rpcping.exe"]
},
"setspn": {
"process_name": ["setspn.exe"]
},
"Net view": {
"cmdline": ["net view"]
},
"remote": {
"process_name": ["remote.exe"]
},
"SharpHound": {
"process_name": ["sharphound.exe"]
},
"winexesvc": {
"process_name": ["winexesvc.exe"]
},
"mimikatz": {
"internal_name": ["mimikatz"]
},
"tscon": {
"process_name": ["tscon.exe"]
},
"msxsl": {
"process_name": ["msxsl.exe"]
},
"uptime": {
"process_name": ["uptime.exe"]
},
"flmtc": {
"process_name": ["flmtc.exe"]
},
"takeown": {
"process_name": ["takeown.exe"]
},
"jjs": {
"process_name": ["jjs.exe"]
},
"nps - powershell": {
"process_name": ["nps.exe"],
"product_name": ["Not Powershell"]
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment