Manual
search
⌘Ctrlk
Manual
  • BluSapphire Manuals
  • BluSapphire
    • Detections
    • Roles & Permissions
    • Knowledge Base
  • BluGenie
    • Full Function List
    • Functions by Category
    • Artifacts
      • Example Template
      • Tactical Artifacts by Category
        • Combination Query
        • EventLog Query
        • File and Folder Query
          • Query for malicious file types in all users and system temp directories
          • Query Malicious file types from any directory not including the default OS and Install directories
          • Query all users for their Powershell Profile content for Powershell, Powershell_ISE, and VS Code
          • Query to Determine if any lolbin files are installed outside the normal OS and Program Files dir's
        • Network Query
        • Process Query
        • Registry Query
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. BluGeniechevron-right
  2. Artifactschevron-right
  3. Tactical Artifacts by Category

File and Folder Query

Query for malicious file types in all users and system temp directorieschevron-rightQuery Malicious file types from any directory not including the default OS and Install directorieschevron-rightQuery all users for their Powershell Profile content for Powershell, Powershell_ISE, and VS Codechevron-rightQuery to Determine if any lolbin files are installed outside the normal OS and Program Files dir'schevron-right
PreviousQuery the Windows System Log for 104, 517, 1102chevron-leftNextQuery for malicious file types in all users and system temp directorieschevron-right

Last updated 3 years ago