'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2025-11-18 | |
| Rule Name: | Suspicious PowerShell Invocation Detection | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | PowerShell is a command-line shell and scripting environment released by Microsoft, enabling command-line users and script writers to leverage the powerful capabilities of the .NET Framework. Due to its robust functionalities and widespread integration into various systems, PowerShell is frequently exploited by attackers to execute malicious commands.This rule is used to detect suspicious calls to PowerShell in HTTP requests. | |
| Impact: | An attacker could exploit this vulnerability to have unspecified effect. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | ||
| Solutions |
|---|
| Please contact the software vendor to update the software patch. |