Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Adversaries may attempt to clear the command history of compromised hosts to conceal the actions that they have performed during an attack. This content will detect if PowerShell's history was cleared, disabled, or modified.
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Intel471 |
| ID | ccdd03de-8fbf-436b-99ba-00dfee83d42f |
| Tactics | DefenseEvasion |
| Techniques | T1070 |
| Required Connectors | SecurityEvents, WindowsSecurityEvents |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|
SecurityEvent |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊