SIGN IN SIGN UP
posh_ps_aadinternals_cmdlets_execution.yml
posh_ps_access_to_browser_login_data.yml
posh_ps_active_directory_module_dll_import.yml
posh_ps_add_dnsclient_rule.yml
posh_ps_add_windows_capability.yml
posh_ps_adrecon_execution.yml
posh_ps_amsi_bypass_pattern_nov22.yml
posh_ps_amsi_null_bits_bypass.yml
posh_ps_apt_silence_eda.yml
posh_ps_as_rep_roasting.yml
posh_ps_audio_exfiltration.yml
posh_ps_automated_collection.yml
posh_ps_capture_screenshots.yml
posh_ps_clear_powershell_history.yml
posh_ps_clearing_windows_console_history.yml
posh_ps_cmdlet_scheduled_task.yml
posh_ps_computer_discovery_get_adcomputer.yml
posh_ps_copy_item_system_directory.yml
posh_ps_cor_profiler.yml
posh_ps_create_local_user.yml
posh_ps_create_volume_shadow_copy.yml
posh_ps_detect_vm_env.yml
posh_ps_directorysearcher.yml
posh_ps_directoryservices_accountmanagement.yml
posh_ps_disable_psreadline_command_history.yml
posh_ps_disable_windows_optional_feature.yml
posh_ps_dotnet_assembly_from_file.yml
posh_ps_download_com_cradles.yml
posh_ps_dsinternals_cmdlets.yml
posh_ps_dump_password_windows_credential_manager.yml
posh_ps_enable_psremoting.yml
posh_ps_enable_susp_windows_optional_feature.yml
posh_ps_enumerate_password_windows_credential_manager.yml
posh_ps_etw_trace_evasion.yml
posh_ps_export_certificate.yml
posh_ps_frombase64string_archive.yml
posh_ps_get_acl_service.yml
posh_ps_get_adcomputer.yml
posh_ps_get_adgroup.yml
posh_ps_get_adreplaccount.yml
posh_ps_get_childitem_bookmarks.yml
posh_ps_get_process_security_software_discovery.yml
posh_ps_hktl_rubeus.yml
posh_ps_hktl_winpwn.yml
posh_ps_hotfix_enum.yml
posh_ps_icmp_exfiltration.yml
posh_ps_import_module_susp_dirs.yml
posh_ps_install_unsigned_appx_packages.yml
posh_ps_invoke_command_remote.yml
posh_ps_invoke_dnsexfiltration.yml
posh_ps_invoke_obfuscation_clip.yml
posh_ps_invoke_obfuscation_obfuscated_iex.yml
posh_ps_invoke_obfuscation_stdin.yml
posh_ps_invoke_obfuscation_var.yml
posh_ps_invoke_obfuscation_via_compress.yml
posh_ps_invoke_obfuscation_via_rundll.yml
posh_ps_invoke_obfuscation_via_stdin.yml
posh_ps_invoke_obfuscation_via_use_clip.yml
posh_ps_invoke_obfuscation_via_use_mhsta.yml
posh_ps_invoke_obfuscation_via_use_rundll32.yml
posh_ps_invoke_obfuscation_via_var.yml
posh_ps_keylogging.yml
posh_ps_localuser.yml
posh_ps_mailboxexport_share.yml
posh_ps_malicious_commandlets.yml
posh_ps_malicious_keywords.yml
posh_ps_memorydump_getstoragediagnosticinfo.yml
posh_ps_modify_group_policy_settings.yml
posh_ps_msxml_com.yml
posh_ps_nishang_malicious_commandlets.yml
posh_ps_ntfs_ads_access.yml
posh_ps_office_comobject_registerxll.yml
posh_ps_packet_capture.yml
posh_ps_potential_invoke_mimikatz.yml
posh_ps_potential_unconstrained_delegation_discovery.yml
posh_ps_powershell_web_access_installation.yml
posh_ps_powerview_malicious_commandlets.yml
posh_ps_prompt_credentials.yml
posh_ps_psasyncshell.yml
posh_ps_psattack.yml
posh_ps_remote_session_creation.yml
posh_ps_remotefxvgpudisablement_abuse.yml
posh_ps_request_kerberos_ticket.yml
posh_ps_resolve_list_of_ip_from_file.yml
posh_ps_root_certificate_installed.yml
posh_ps_run_from_mount_diskimage.yml
posh_ps_script_with_upload_capabilities.yml
posh_ps_sensitive_file_discovery.yml
posh_ps_set_acl_susp_location.yml
posh_ps_set_acl.yml
posh_ps_set_policies_to_unsecure_level.yml
posh_ps_shellcode_b64.yml
posh_ps_shellintel_malicious_commandlets.yml
posh_ps_software_discovery.yml
posh_ps_store_file_in_alternate_data_stream.yml
posh_ps_susp_ace_tampering.yml
posh_ps_susp_ad_group_reco.yml
posh_ps_susp_alias_obfscuation.yml
posh_ps_susp_clear_eventlog.yml
posh_ps_susp_directory_enum.yml
posh_ps_susp_download.yml
posh_ps_susp_execute_batch_script.yml
posh_ps_susp_extracting.yml
posh_ps_susp_follina_execution.yml
posh_ps_susp_get_addefaultdomainpasswordpolicy.yml
posh_ps_susp_get_current_user.yml
posh_ps_susp_get_gpo.yml
posh_ps_susp_get_process.yml
posh_ps_susp_getprocess_lsass.yml
posh_ps_susp_gettypefromclsid.yml
posh_ps_susp_hyper_v_condlet.yml
posh_ps_susp_invocation_generic.yml
posh_ps_susp_invocation_specific.yml
posh_ps_susp_invoke_webrequest_useragent.yml
posh_ps_susp_iofilestream.yml
posh_ps_susp_keylogger_activity.yml
posh_ps_susp_keywords.yml
posh_ps_susp_local_group_reco.yml
posh_ps_susp_mail_acces.yml
posh_ps_susp_mount_diskimage.yml
posh_ps_susp_mounted_share_deletion.yml
posh_ps_susp_networkcredential.yml
posh_ps_susp_new_psdrive.yml
posh_ps_susp_proxy_scripts.yml
posh_ps_susp_recon_export.yml
posh_ps_susp_remove_adgroupmember.yml
posh_ps_susp_service_dacl_modification_set_service.yml
posh_ps_susp_set_alias.yml
posh_ps_susp_smb_share_reco.yml
posh_ps_susp_ssl_keyword.yml
posh_ps_susp_start_process.yml
posh_ps_susp_unblock_file.yml
posh_ps_susp_wallpaper.yml
posh_ps_susp_win32_pnpentity.yml
posh_ps_susp_win32_shadowcopy_deletion.yml
posh_ps_susp_windowstyle.yml
posh_ps_susp_write_eventlog.yml
posh_ps_susp_zip_compress.yml
posh_ps_syncappvpublishingserver_exe.yml
posh_ps_tamper_windows_defender_rem_mp.yml
posh_ps_tamper_windows_defender_set_mp.yml
posh_ps_test_netconnection.yml
posh_ps_timestomp.yml
posh_ps_user_discovery_get_aduser.yml
posh_ps_user_profile_tampering.yml
posh_ps_using_set_service_to_hide_services.yml
posh_ps_vbscript_registry_modification.yml
posh_ps_veeam_credential_dumping_script.yml
posh_ps_web_request_cmd_and_cmdlets.yml
posh_ps_win_api_susp_access.yml
posh_ps_win_defender_exclusions_added.yml
posh_ps_win32_nteventlogfile_usage.yml
posh_ps_win32_product_install_msi.yml
posh_ps_windows_firewall_profile_disabled.yml
posh_ps_winlogon_helper_dll.yml
posh_ps_wmi_persistence.yml
posh_ps_wmi_unquoted_service_search.yml
posh_ps_wmimplant.yml
posh_ps_x509enrollment.yml
posh_ps_xml_iex.yml