Manual
search
Ctrlk
  • BluSapphire Manuals
  • BluSapphire
    • Detectionschevron-right
    • Roles & Permissions
    • Knowledge Base
  • BluGenie
    • Full Function Listchevron-right
    • Functions by Categorychevron-right
    • Artifactschevron-right
      • Example Template
      • Tactical Artifacts by Categorychevron-right
        • Combination Querychevron-right
        • EventLog Querychevron-right
        • File and Folder Querychevron-right
          • Query for malicious file types in all users and system temp directories
          • Query Malicious file types from any directory not including the default OS and Install directories
          • Query all users for their Powershell Profile content for Powershell, Powershell_ISE, and VS Code
          • Query to Determine if any lolbin files are installed outside the normal OS and Program Files dir's
        • Network Querychevron-right
        • Process Querychevron-right
        • Registry Querychevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. BluGeniechevron-right
  2. Artifactschevron-right
  3. Tactical Artifacts by Category

File and Folder Query

Query for malicious file types in all users and system temp directorieschevron-rightQuery Malicious file types from any directory not including the default OS and Install directorieschevron-rightQuery all users for their Powershell Profile content for Powershell, Powershell_ISE, and VS Codechevron-rightQuery to Determine if any lolbin files are installed outside the normal OS and Program Files dir'schevron-right
PreviousQuery the Windows System Log for 104, 517, 1102chevron-leftNextQuery for malicious file types in all users and system temp directorieschevron-right

Last updated 3 years ago