Can your SOC see an erased trail?
Delete your own PowerShell history file, then check your alerts
Copy one line. Run it on a machine you own. Then open your alerts and find out something true about your coverage — in about a minute, with nobody watching but you.
Remove-Item (Get-PSReadlineOption).HistorySavePathDelete your own PowerShell history file, then check your alerts
Every technique here is public, documented tradecraft — MITRE ATT&CK and the public advisories name it long before we do. Every detection is expressed in Sigma, the open, vendor-neutral format, so your team can translate it into whatever you run.
We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
Detection logic on these pages is Sigma, and the rules come from the SigmaHQ rule set, used under the Detection Rule License 1.1 — https://github.com/SigmaHQ/Detection-Rule-License
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI