Can your SOC see an erased trail?
Delete your own PowerShell history file, then check your alerts
Copy one line. Run it on a machine you own. Then open your alerts and find out something true about your coverage — in about a minute, with nobody watching but you.
Remove-Item (Get-PSReadlineOption).HistorySavePathDelete your own PowerShell history file, then check your alerts
Run net user and whoami /all to list local accounts
Run net view to enumerate reachable shares and sessions
Create a harmless scheduled task with schtasks, then delete it
Run systeminfo to read the machine's full specification
Pipe tasklist into findstr to filter the running process list
Run net use to list connections this machine already holds
Run ipconfig /all, arp -a and route print
Filter the process list for the name of a security product
Import a one-value registry file with reg import, then delete it
Encode a harmless file to base64 with certutil, then delete both
Run a PowerShell command line that decodes its own base64 string
Read the last lines of your own PowerShell console history
Every technique here is public, documented tradecraft — MITRE ATT&CK and the public advisories name it long before we do. Every detection is expressed in Sigma, the open, vendor-neutral format, so your team can translate it into whatever you run.
We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.
Detection logic on these pages is Sigma, and the rules come from the SigmaHQ rule set, used under the Detection Rule License 1.1 — https://github.com/SigmaHQ/Detection-Rule-License
CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI