
Output redirection from cmd.exe is not captured on the command line unless it is part of an argument (e.g. cmd.exe /c "whoami > out.txt").
So a SIGMA rule like this one will work 60% of the time all the time.
github.com/SigmaHQ/sigma/…
English
Adam Swan
753 posts

@acalarch
https://t.co/Fuai6SJzcJ


















