| where InitiatingProcessFileName =~ “wscript.exe”
| where FileName =~ “Powershell.exe”
| where ProcessCommandLine has_any(“invoke-webrequesr”,”iwr”)
looking for Wscript with a powershell childprocess to execute a payload
https://redcanary.com/blog/tax-season-phishing/
| where InitiatingProcessFileName =~ “wscript.exe”
| where FileName =~ “Powershell.exe”
| where ProcessCommandLine has_any(“invoke-webrequesr”,”iwr”)
looking for Wscript with a powershell childprocess to execute a payload
https://redcanary.com/blog/tax-season-phishing/
☁️ Watch for giveaways from community here & other socials
☁️ Create awesome & authentic content & engage the community & maybe you’ll get some in your box
☁️ Ask friends if they have extras
☁️ Kindly don’t ask team for them
☁️ Wait
☁️ Watch for giveaways from community here & other socials
☁️ Create awesome & authentic content & engage the community & maybe you’ll get some in your box
☁️ Ask friends if they have extras
☁️ Kindly don’t ask team for them
☁️ Wait