Skip to content

Instantly share code, notes, and snippets.

@mireaulf
mireaulf / gist:4a2150071b48b6b7573e782ce7d125d1
Last active August 27, 2021 16:37
LimaCharlie.IO - DR rule - RazerInstaller - PrivEsc
op: and
events:
- NEW_PROCESS
rules:
- op is windows
- op: contains
path: event/FILE_PATH
value: powershell.exe
- op: is
path: USER_NAME
### Keybase proof
I hereby claim:
* I am mireaulf on github.
* I am mireaulf (https://keybase.io/mireaulf) on keybase.
* I have a public key whose fingerprint is 1390 E000 4047 636E 99B9 8996 7AEA 3A52 3C02 B674
To claim this, I am signing this object: