cscli scenarios install sigmahq/proc_creation_win_susp_emoji_usage_in_cli_4
1type: trigger2name: sigmahq/proc_creation_win_susp_emoji_usage_in_cli_43description: |4 Detects the usage of emojis in the command line, this could be a sign of potential defense evasion activity.5filter: |6 (evt.Meta.service == 'sysmon' && evt.Parsed.EventID == '1') && (evt.Parsed.CommandLine contains '๐ธ' || evt.Parsed.CommandLine contains '๐น' || evt.Parsed.CommandLine contains '๐ถ' || evt.Parsed.CommandLine contains '๐ท' || evt.Parsed.CommandLine contains '๐ณ' || evt.Parsed.CommandLine contains '๐ฒ' || evt.Parsed.CommandLine contains 'โช๏ธ' || evt.Parsed.CommandLine contains 'โซ๏ธ' || evt.Parsed.CommandLine contains 'โพ๏ธ' || evt.Parsed.CommandLine contains 'โฝ๏ธ' || evt.Parsed.CommandLine contains 'โผ๏ธ' || evt.Parsed.CommandLine contains 'โป๏ธ' || evt.Parsed.CommandLine contains '๐ฅ' || evt.Parsed.CommandLine contains '๐ง' || evt.Parsed.CommandLine contains '๐จ' || evt.Parsed.CommandLine contains '๐ฉ' || evt.Parsed.CommandLine contains '๐ฆ' || evt.Parsed.CommandLine contains '๐ช' || evt.Parsed.CommandLine contains 'โฌ๏ธ' || evt.Parsed.CommandLine contains 'โฌ๏ธ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ฃ' || evt.Parsed.CommandLine contains '๐ข' || evt.Parsed.CommandLine contains '๐โ๐จ' || evt.Parsed.CommandLine contains '๐ฌ' || evt.Parsed.CommandLine contains '๐ญ' || evt.Parsed.CommandLine contains '๐ฏ' || evt.Parsed.CommandLine contains 'โ ๏ธ' || evt.Parsed.CommandLine contains 'โฃ๏ธ' || evt.Parsed.CommandLine contains 'โฅ๏ธ' || evt.Parsed.CommandLine contains 'โฆ๏ธ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ด' || evt.Parsed.CommandLine contains '๐๏ธ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ ' || evt.Parsed.CommandLine contains '๐ก' || evt.Parsed.CommandLine contains '๐ข' || evt.Parsed.CommandLine contains '๐ฃ' || evt.Parsed.CommandLine contains '๐ค' || evt.Parsed.CommandLine contains '๐ฅ' || evt.Parsed.CommandLine contains '๐ฆ' || evt.Parsed.CommandLine contains '๐งโข' || evt.Parsed.CommandLine contains 'โฃ' || evt.Parsed.CommandLine contains 'โค' || evt.Parsed.CommandLine contains 'โฅ' || evt.Parsed.CommandLine contains 'โฆ' || evt.Parsed.CommandLine contains 'โง' || evt.Parsed.CommandLine contains 'โ ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โฏ' || evt.Parsed.CommandLine contains 'โก๏ธ' || evt.Parsed.CommandLine contains 'โฉ' || evt.Parsed.CommandLine contains 'โช' || evt.Parsed.CommandLine contains 'โซ' || evt.Parsed.CommandLine contains 'โฌ' || evt.Parsed.CommandLine contains 'โญ' || evt.Parsed.CommandLine contains 'โฎ' || evt.Parsed.CommandLine contains 'โถ' || evt.Parsed.CommandLine contains 'โท' || evt.Parsed.CommandLine contains 'โต' || evt.Parsed.CommandLine contains 'โธ' || evt.Parsed.CommandLine contains 'โน' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โน' || evt.Parsed.CommandLine contains 'โจ' || evt.Parsed.CommandLine contains 'โพ' || evt.Parsed.CommandLine contains 'โพ' || evt.Parsed.CommandLine contains 'โข' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ ๏ธ' || evt.Parsed.CommandLine contains 'โฃ๏ธ' || evt.Parsed.CommandLine contains 'โฅ๏ธ' || evt.Parsed.CommandLine contains 'โฆ๏ธ' || evt.Parsed.CommandLine contains 'โค' || evt.Parsed.CommandLine contains 'โง' || evt.Parsed.CommandLine contains 'โก' || evt.Parsed.CommandLine contains 'โข' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ ' || evt.Parsed.CommandLine contains '๐ ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains 'โ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐๐ณ๏ธ' || evt.Parsed.CommandLine contains '๐ด' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ฉ' || evt.Parsed.CommandLine contains '๐ณ๏ธโ๐' || evt.Parsed.CommandLine contains '๐ณ๏ธโโง๏ธ' || evt.Parsed.CommandLine contains '๐ดโโ ๏ธ' || evt.Parsed.CommandLine contains '๐ฆ๐ซ' || evt.Parsed.CommandLine contains '๐ฆ๐ฝ' || evt.Parsed.CommandLine contains '๐ฆ๐ฑ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฆ๐ธ' || evt.Parsed.CommandLine contains '๐ฆ๐ฉ' || evt.Parsed.CommandLine contains '๐ฆ๐ด' || evt.Parsed.CommandLine contains '๐ฆ๐ฎ' || evt.Parsed.CommandLine contains '๐ฆ๐ถ' || evt.Parsed.CommandLine contains '๐ฆ๐ฌ' || evt.Parsed.CommandLine contains '๐ฆ๐ท' || evt.Parsed.CommandLine contains '๐ฆ๐ฒ' || evt.Parsed.CommandLine contains '๐ฆ๐ผ' || evt.Parsed.CommandLine contains '๐ฆ๐บ' || evt.Parsed.CommandLine contains '๐ฆ๐น' || evt.Parsed.CommandLine contains '๐ฆ๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ธ' || evt.Parsed.CommandLine contains '๐ง๐ญ' || evt.Parsed.CommandLine contains '๐ง๐ฉ' || evt.Parsed.CommandLine contains '๐ง๐ง' || evt.Parsed.CommandLine contains '๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ช' || evt.Parsed.CommandLine contains '๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ฏ' || evt.Parsed.CommandLine contains '๐ง๐ฒ' || evt.Parsed.CommandLine contains '๐ง๐น' || evt.Parsed.CommandLine contains '๐ง๐ด' || evt.Parsed.CommandLine contains '๐ง๐ฆ' || evt.Parsed.CommandLine contains '๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ท' || evt.Parsed.CommandLine contains '๐ฎ๐ด' || evt.Parsed.CommandLine contains '๐ป๐ฌ' || evt.Parsed.CommandLine contains '๐ง๐ณ' || evt.Parsed.CommandLine contains '๐ง๐ฌ' || evt.Parsed.CommandLine contains '๐ง๐ซ' || evt.Parsed.CommandLine contains '๐ง๐ฎ' || evt.Parsed.CommandLine contains '๐ฐ๐ญ' || evt.Parsed.CommandLine contains '๐จ๐ฒ' || evt.Parsed.CommandLine contains '๐จ๐ฆ' || evt.Parsed.CommandLine contains '๐ฎ๐จ' || evt.Parsed.CommandLine contains '๐จ๐ป' || evt.Parsed.CommandLine contains '๐ง๐ถ' || evt.Parsed.CommandLine contains '๐ฐ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ซ' || evt.Parsed.CommandLine contains '๐น๐ฉ' || evt.Parsed.CommandLine contains '๐จ๐ฑ' || evt.Parsed.CommandLine contains '๐จ๐ณ' || evt.Parsed.CommandLine contains '๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐จ' || evt.Parsed.CommandLine contains '๐จ๐ด' || evt.Parsed.CommandLine contains '๐ฐ๐ฒ' || evt.Parsed.CommandLine contains '๐จ๐ฌ' || evt.Parsed.CommandLine contains '๐จ๐ฉ' || evt.Parsed.CommandLine contains '๐จ๐ฐ' || evt.Parsed.CommandLine contains '๐จ๐ท' || evt.Parsed.CommandLine contains '๐จ๐ฎ' || evt.Parsed.CommandLine contains '๐ญ๐ท' || evt.Parsed.CommandLine contains '๐จ๐บ' || evt.Parsed.CommandLine contains '๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฐ' || evt.Parsed.CommandLine contains '๐ฉ๐ฏ' || evt.Parsed.CommandLine contains '๐ฉ๐ฒ' || evt.Parsed.CommandLine contains '๐ฉ๐ด' || evt.Parsed.CommandLine contains '๐ช๐จ' || evt.Parsed.CommandLine contains '๐ช๐ฌ' || evt.Parsed.CommandLine contains '๐ธ๐ป' || evt.Parsed.CommandLine contains '๐ฌ๐ถ' || evt.Parsed.CommandLine contains '๐ช๐ท' || evt.Parsed.CommandLine contains '๐ช๐ช' || evt.Parsed.CommandLine contains '๐ช๐น' || evt.Parsed.CommandLine contains '๐ช๐บ' || evt.Parsed.CommandLine contains '๐ซ๐ฐ' || evt.Parsed.CommandLine contains '๐ซ๐ด' || evt.Parsed.CommandLine contains '๐ซ๐ฏ' || evt.Parsed.CommandLine contains '๐ซ๐ฎ' || evt.Parsed.CommandLine contains '๐ซ๐ท' || evt.Parsed.CommandLine contains '๐ฌ๐ซ' || evt.Parsed.CommandLine contains '๐ต๐ซ' || evt.Parsed.CommandLine contains '๐น๐ซ' || evt.Parsed.CommandLine contains '๐ฌ๐ฆ' || evt.Parsed.CommandLine contains '๐ฌ๐ฒ' || evt.Parsed.CommandLine contains '๐ฌ๐ช' || evt.Parsed.CommandLine contains '๐ฉ๐ช' || evt.Parsed.CommandLine contains '๐ฌ๐ญ' || evt.Parsed.CommandLine contains '๐ฌ๐ฎ' || evt.Parsed.CommandLine contains '๐ฌ๐ท' || evt.Parsed.CommandLine contains '๐ฌ๐ฑ' || evt.Parsed.CommandLine contains '๐ฌ๐ฉ' || evt.Parsed.CommandLine contains '๐ฌ๐ต' || evt.Parsed.CommandLine contains '๐ฌ๐บ' || evt.Parsed.CommandLine contains '๐ฌ๐น' || evt.Parsed.CommandLine contains '๐ฌ๐ฌ' || evt.Parsed.CommandLine contains '๐ฌ๐ณ' || evt.Parsed.CommandLine contains '๐ฌ๐ผ' || evt.Parsed.CommandLine contains '๐ฌ๐พ' || evt.Parsed.CommandLine contains '๐ญ๐น' || evt.Parsed.CommandLine contains '๐ญ๐ณ' || evt.Parsed.CommandLine contains '๐ญ๐ฐ' || evt.Parsed.CommandLine contains '๐ญ๐บ' || evt.Parsed.CommandLine contains '๐ฎ๐ธ' || evt.Parsed.CommandLine contains '๐ฎ๐ณ' || evt.Parsed.CommandLine contains '๐ฎ๐ฉ' || evt.Parsed.CommandLine contains '๐ฎ๐ท' || evt.Parsed.CommandLine contains '๐ฎ๐ถ' || evt.Parsed.CommandLine contains '๐ฎ๐ช' || evt.Parsed.CommandLine contains '๐ฎ๐ฒ' || evt.Parsed.CommandLine contains '๐ฎ๐ฑ' || evt.Parsed.CommandLine contains '๐ฎ๐น' || evt.Parsed.CommandLine contains '๐ฏ๐ฒ' || evt.Parsed.CommandLine contains '๐ฏ๐ต' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ฏ๐ช' || evt.Parsed.CommandLine contains '๐ฏ๐ด' || evt.Parsed.CommandLine contains '๐ฐ๐ฟ' || evt.Parsed.CommandLine contains '๐ฐ๐ช' || evt.Parsed.CommandLine contains '๐ฐ๐ฎ' || evt.Parsed.CommandLine contains '๐ฝ๐ฐ' || evt.Parsed.CommandLine contains '๐ฐ๐ผ' || evt.Parsed.CommandLine contains '๐ฐ๐ฌ' || evt.Parsed.CommandLine contains '๐ฑ๐ฆ' || evt.Parsed.CommandLine contains '๐ฑ๐ป' || evt.Parsed.CommandLine contains '๐ฑ๐ง' || evt.Parsed.CommandLine contains '๐ฑ๐ธ' || evt.Parsed.CommandLine contains '๐ฑ๐ท' || evt.Parsed.CommandLine contains '๐ฑ๐พ' || evt.Parsed.CommandLine contains '๐ฑ๐ฎ' || evt.Parsed.CommandLine contains '๐ฑ๐น' || evt.Parsed.CommandLine contains '๐ฑ๐บ' || evt.Parsed.CommandLine contains '๐ฒ๐ด' || evt.Parsed.CommandLine contains '๐ฒ๐ฐ' || evt.Parsed.CommandLine contains '๐ฒ๐ฌ' || evt.Parsed.CommandLine contains '๐ฒ๐ผ' || evt.Parsed.CommandLine contains '๐ฒ๐พ' || evt.Parsed.CommandLine contains '๐ฒ๐ป' || evt.Parsed.CommandLine contains '๐ฒ๐ฑ' || evt.Parsed.CommandLine contains '๐ฒ๐น' || evt.Parsed.CommandLine contains '๐ฒ๐ญ' || evt.Parsed.CommandLine contains '๐ฒ๐ถ' || evt.Parsed.CommandLine contains '๐ฒ๐ท' || evt.Parsed.CommandLine contains '๐ฒ๐บ' || evt.Parsed.CommandLine contains '๐พ๐น' || evt.Parsed.CommandLine contains '๐ฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซ๐ฒ' || evt.Parsed.CommandLine contains '๐ฒ๐ฉ' || evt.Parsed.CommandLine contains '๐ฒ๐จ' || evt.Parsed.CommandLine contains '๐ฒ๐ณ' || evt.Parsed.CommandLine contains '๐ฒ๐ช' || evt.Parsed.CommandLine contains '๐ฒ๐ธ' || evt.Parsed.CommandLine contains '๐ฒ๐ฆ' || evt.Parsed.CommandLine contains '๐ฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ฒ๐ฒ' || evt.Parsed.CommandLine contains '๐ณ๐ฆ' || evt.Parsed.CommandLine contains '๐ณ๐ท' || evt.Parsed.CommandLine contains '๐ณ๐ต' || evt.Parsed.CommandLine contains '๐ณ๐ฑ' || evt.Parsed.CommandLine contains '๐ณ๐จ' || evt.Parsed.CommandLine contains '๐ณ๐ฟ' || evt.Parsed.CommandLine contains '๐ณ๐ฎ' || evt.Parsed.CommandLine contains '๐ณ๐ช' || evt.Parsed.CommandLine contains '๐ณ๐ฌ' || evt.Parsed.CommandLine contains '๐ณ๐บ' || evt.Parsed.CommandLine contains '๐ณ๐ซ' || evt.Parsed.CommandLine contains '๐ฐ๐ต' || evt.Parsed.CommandLine contains '๐ฒ๐ต' || evt.Parsed.CommandLine contains '๐ณ๐ด' || evt.Parsed.CommandLine contains '๐ด๐ฒ' || evt.Parsed.CommandLine contains '๐ต๐ฐ' || evt.Parsed.CommandLine contains '๐ต๐ผ' || evt.Parsed.CommandLine contains '๐ต๐ธ' || evt.Parsed.CommandLine contains '๐ต๐ฆ' || evt.Parsed.CommandLine contains '๐ต๐ฌ' || evt.Parsed.CommandLine contains '๐ต๐พ' || evt.Parsed.CommandLine contains '๐ต๐ช' || evt.Parsed.CommandLine contains '๐ต๐ญ' || evt.Parsed.CommandLine contains '๐ต๐ณ' || evt.Parsed.CommandLine contains '๐ต๐ฑ' || evt.Parsed.CommandLine contains '๐ต๐น' || evt.Parsed.CommandLine contains '๐ต๐ท' || evt.Parsed.CommandLine contains '๐ถ๐ฆ' || evt.Parsed.CommandLine contains '๐ท๐ช' || evt.Parsed.CommandLine contains '๐ท๐ด' || evt.Parsed.CommandLine contains '๐ท๐บ' || evt.Parsed.CommandLine contains '๐ท๐ผ' || evt.Parsed.CommandLine contains '๐ผ๐ธ' || evt.Parsed.CommandLine contains '๐ธ๐ฒ' || evt.Parsed.CommandLine contains '๐ธ๐ฆ' || evt.Parsed.CommandLine contains '๐ธ๐ณ' || evt.Parsed.CommandLine contains '๐ท๐ธ' || evt.Parsed.CommandLine contains '๐ธ๐จ' || evt.Parsed.CommandLine contains '๐ธ๐ฑ' || evt.Parsed.CommandLine contains '๐ธ๐ฌ' || evt.Parsed.CommandLine contains '๐ธ๐ฝ' || evt.Parsed.CommandLine contains '๐ธ๐ฐ' || evt.Parsed.CommandLine contains '๐ธ๐ฎ' || evt.Parsed.CommandLine contains '๐ฌ๐ธ' || evt.Parsed.CommandLine contains '๐ธ๐ง' || evt.Parsed.CommandLine contains '๐ธ๐ด' || evt.Parsed.CommandLine contains '๐ฟ๐ฆ' || evt.Parsed.CommandLine contains '๐ฐ๐ท' || evt.Parsed.CommandLine contains '๐ธ๐ธ' || evt.Parsed.CommandLine contains '๐ช๐ธ' || evt.Parsed.CommandLine contains '๐ฑ๐ฐ' || evt.Parsed.CommandLine contains '๐ง๐ฑ' || evt.Parsed.CommandLine contains '๐ธ๐ญ' || evt.Parsed.CommandLine contains '๐ฐ๐ณ' || evt.Parsed.CommandLine contains '๐ฑ๐จ' || evt.Parsed.CommandLine contains '๐ต๐ฒ' || evt.Parsed.CommandLine contains '๐ป๐จ' || evt.Parsed.CommandLine contains '๐ธ๐ฉ' || evt.Parsed.CommandLine contains '๐ธ๐ท' || evt.Parsed.CommandLine contains '๐ธ๐ฟ' || evt.Parsed.CommandLine contains '๐ธ๐ช' || evt.Parsed.CommandLine contains '๐จ๐ญ' || evt.Parsed.CommandLine contains '๐ธ๐พ' || evt.Parsed.CommandLine contains '๐น๐ผ' || evt.Parsed.CommandLine contains '๐น๐ฏ' || evt.Parsed.CommandLine contains '๐น๐ฟ' || evt.Parsed.CommandLine contains '๐น๐ญ' || evt.Parsed.CommandLine contains '๐น๐ฑ' || evt.Parsed.CommandLine contains '๐น๐ฌ' || evt.Parsed.CommandLine contains '๐น๐ฐ' || evt.Parsed.CommandLine contains '๐น๐ด' || evt.Parsed.CommandLine contains '๐น๐น' || evt.Parsed.CommandLine contains '๐น๐ณ' || evt.Parsed.CommandLine contains '๐น๐ท' || evt.Parsed.CommandLine contains '๐น๐ฒ' || evt.Parsed.CommandLine contains '๐น๐จ' || evt.Parsed.CommandLine contains '๐น๐ป' || evt.Parsed.CommandLine contains '๐ป๐ฎ' || evt.Parsed.CommandLine contains '๐บ๐ฌ' || evt.Parsed.CommandLine contains '๐บ๐ฆ' || evt.Parsed.CommandLine contains '๐ฆ๐ช' || evt.Parsed.CommandLine contains '๐ฌ๐ง' || evt.Parsed.CommandLine contains '๐ด๓ ง๓ ข๓ ฅ๓ ฎ๓ ง๓ ฟ' || evt.Parsed.CommandLine contains '๐ด๓ ง๓ ข๓ ณ๓ ฃ๓ ด๓ ฟ' || evt.Parsed.CommandLine contains '๐ด๓ ง๓ ข๓ ท๓ ฌ๓ ณ๓ ฟ' || evt.Parsed.CommandLine contains '๐บ๐ณ' || evt.Parsed.CommandLine contains '๐บ๐ธ' || evt.Parsed.CommandLine contains '๐บ๐พ' || evt.Parsed.CommandLine contains '๐บ๐ฟ' || evt.Parsed.CommandLine contains '๐ป๐บ' || evt.Parsed.CommandLine contains '๐ป๐ฆ' || evt.Parsed.CommandLine contains '๐ป๐ช' || evt.Parsed.CommandLine contains '๐ป๐ณ' || evt.Parsed.CommandLine contains '๐ผ๐ซ' || evt.Parsed.CommandLine contains '๐ช๐ญ' || evt.Parsed.CommandLine contains '๐พ๐ช' || evt.Parsed.CommandLine contains '๐ฟ๐ฒ' || evt.Parsed.CommandLine contains '๐ฟ๐ผ๐ซ ' || evt.Parsed.CommandLine contains '๐ซข' || evt.Parsed.CommandLine contains '๐ซฃ' || evt.Parsed.CommandLine contains '๐ซก' || evt.Parsed.CommandLine contains '๐ซฅ' || evt.Parsed.CommandLine contains '๐ซค' || evt.Parsed.CommandLine contains '๐ฅน' || evt.Parsed.CommandLine contains '๐ซฑ' || evt.Parsed.CommandLine contains '๐ซฑ๐ป' || evt.Parsed.CommandLine contains '๐ซฑ๐ผ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฑ๐พ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฟ' || evt.Parsed.CommandLine contains '๐ซฒ' || evt.Parsed.CommandLine contains '๐ซฒ๐ป' || evt.Parsed.CommandLine contains '๐ซฒ๐ผ' || evt.Parsed.CommandLine contains '๐ซฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฒ๐พ' || evt.Parsed.CommandLine contains '๐ซฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ซณ' || evt.Parsed.CommandLine contains '๐ซณ๐ป' || evt.Parsed.CommandLine contains '๐ซณ๐ผ' || evt.Parsed.CommandLine contains '๐ซณ๐ฝ' || evt.Parsed.CommandLine contains '๐ซณ๐พ' || evt.Parsed.CommandLine contains '๐ซณ๐ฟ' || evt.Parsed.CommandLine contains '๐ซด' || evt.Parsed.CommandLine contains '๐ซด๐ป' || evt.Parsed.CommandLine contains '๐ซด๐ผ' || evt.Parsed.CommandLine contains '๐ซด๐ฝ' || evt.Parsed.CommandLine contains '๐ซด๐พ' || evt.Parsed.CommandLine contains '๐ซด๐ฟ' || evt.Parsed.CommandLine contains '๐ซฐ' || evt.Parsed.CommandLine contains '๐ซฐ๐ป' || evt.Parsed.CommandLine contains '๐ซฐ๐ผ' || evt.Parsed.CommandLine contains '๐ซฐ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฐ๐พ' || evt.Parsed.CommandLine contains '๐ซฐ๐ฟ' || evt.Parsed.CommandLine contains '๐ซต' || evt.Parsed.CommandLine contains '๐ซต๐ป' || evt.Parsed.CommandLine contains '๐ซต๐ผ' || evt.Parsed.CommandLine contains '๐ซต๐ฝ' || evt.Parsed.CommandLine contains '๐ซต๐พ' || evt.Parsed.CommandLine contains '๐ซต๐ฟ' || evt.Parsed.CommandLine contains '๐ซถ' || evt.Parsed.CommandLine contains '๐ซถ๐ป' || evt.Parsed.CommandLine contains '๐ซถ๐ผ' || evt.Parsed.CommandLine contains '๐ซถ๐ฝ' || evt.Parsed.CommandLine contains '๐ซถ๐พ' || evt.Parsed.CommandLine contains '๐ซถ๐ฟ' || evt.Parsed.CommandLine contains '๐ค๐ป' || evt.Parsed.CommandLine contains '๐ค๐ผ' || evt.Parsed.CommandLine contains '๐ค๐ฝ' || evt.Parsed.CommandLine contains '๐ค๐พ' || evt.Parsed.CommandLine contains '๐ค๐ฟ' || evt.Parsed.CommandLine contains '๐ซฑ๐ปโ๐ซฒ๐ผ' || evt.Parsed.CommandLine contains '๐ซฑ๐ปโ๐ซฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฑ๐ปโ๐ซฒ๐พ' || evt.Parsed.CommandLine contains '๐ซฑ๐ปโ๐ซฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ซฑ๐ผโ๐ซฒ๐ป' || evt.Parsed.CommandLine contains '๐ซฑ๐ผโ๐ซฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฑ๐ผโ๐ซฒ๐พ' || evt.Parsed.CommandLine contains '๐ซฑ๐ผโ๐ซฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฝโ๐ซฒ๐ป' || evt.Parsed.CommandLine contains '๐ซฑ๐ฝโ๐ซฒ๐ผ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฝโ๐ซฒ๐พ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฝโ๐ซฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ซฑ๐พโ๐ซฒ๐ป' || evt.Parsed.CommandLine contains '๐ซฑ๐พโ๐ซฒ๐ผ' || evt.Parsed.CommandLine contains '๐ซฑ๐พโ๐ซฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฑ๐พโ๐ซฒ๐ฟ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฟโ๐ซฒ๐ป' || evt.Parsed.CommandLine contains '๐ซฑ๐ฟโ๐ซฒ๐ผ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฟโ๐ซฒ๐ฝ' || evt.Parsed.CommandLine contains '๐ซฑ๐ฟโ๐ซฒ๐พ' || evt.Parsed.CommandLine contains '๐ซฆ' || evt.Parsed.CommandLine contains '๐ซ ' || evt.Parsed.CommandLine contains '๐ซ ๐ป' || evt.Parsed.CommandLine contains '๐ซ ๐ผ' || evt.Parsed.CommandLine contains '๐ซ ๐ฝ' || evt.Parsed.CommandLine contains '๐ซ ๐พ' || evt.Parsed.CommandLine contains '๐ซ ๐ฟ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐ซ๐ป' || evt.Parsed.CommandLine contains '๐ซ๐ผ' || evt.Parsed.CommandLine contains '๐ซ๐ฝ' || evt.Parsed.CommandLine contains '๐ซ๐พ' || evt.Parsed.CommandLine contains '๐ซ๐ฟ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐ซ๐ป' || evt.Parsed.CommandLine contains '๐ซ๐ผ' || evt.Parsed.CommandLine contains '๐ซ๐ฝ' || evt.Parsed.CommandLine contains '๐ซ๐พ' || evt.Parsed.CommandLine contains '๐ซ๐ฟ' || evt.Parsed.CommandLine contains '๐ง' || evt.Parsed.CommandLine contains '๐ชธ' || evt.Parsed.CommandLine contains '๐ชท' || evt.Parsed.CommandLine contains '๐ชน' || evt.Parsed.CommandLine contains '๐ชบ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐ซ' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐' || evt.Parsed.CommandLine contains '๐ชฌ' || evt.Parsed.CommandLine contains '๐ชฉ' || evt.Parsed.CommandLine contains '๐ชซ' || evt.Parsed.CommandLine contains '๐ฉผ' || evt.Parsed.CommandLine contains '๐ฉป' || evt.Parsed.CommandLine contains '๐ซง' || evt.Parsed.CommandLine contains '๐ชช' || evt.Parsed.CommandLine contains '๐ฐ' || evt.Parsed.CommandLine contains '๐ฎโ๐จ' || evt.Parsed.CommandLine contains '๐ตโ๐ซ' || evt.Parsed.CommandLine contains '๐ถโ๐ซ๏ธ' || evt.Parsed.CommandLine contains 'โค๏ธโ๐ฅ' || evt.Parsed.CommandLine contains 'โค๏ธโ๐ฉน' || evt.Parsed.CommandLine contains '๐งโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ปโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ผโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐พโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโ๏ธ' || evt.Parsed.CommandLine contains '๐งโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ปโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ผโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐พโโ๏ธ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโ๏ธ' || evt.Parsed.CommandLine contains '๐๐ป' || evt.Parsed.CommandLine contains '๐๐ผ' || evt.Parsed.CommandLine contains '๐๐ฝ' || evt.Parsed.CommandLine contains '๐๐พ' || evt.Parsed.CommandLine contains '๐๐ฟ' || evt.Parsed.CommandLine contains '๐๐ป' || evt.Parsed.CommandLine contains '๐๐ผ' || evt.Parsed.CommandLine contains '๐๐ฝ' || evt.Parsed.CommandLine contains '๐๐พ' || evt.Parsed.CommandLine contains '๐๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐ง๐พ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ปโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ผโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ฝโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐พโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐จ๐ฟโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ปโโค๏ธโ๐โ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ผโโค๏ธโ๐โ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฝโโค๏ธโ๐โ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐พโโค๏ธโ๐โ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐จ๐ฟ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ป' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ผ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฝ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐พ' || evt.Parsed.CommandLine contains '๐ฉ๐ฟโโค๏ธโ๐โ๐ฉ๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐โ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐โ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐โ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ปโโค๏ธโ๐โ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐โ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐โ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐โ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ผโโค๏ธโ๐โ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐โ๐ง๐พ' || evt.Parsed.CommandLine contains '๐ง๐ฝโโค๏ธโ๐โ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐โ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐โ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐โ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐พโโค๏ธโ๐โ๐ง๐ฟ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ป' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ผ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐โ๐ง๐ฝ' || evt.Parsed.CommandLine contains '๐ง๐ฟโโค๏ธโ๐โ๐ง๐พ')7blackhole: 2m8#status: test9labels:10 service: windows11 confidence: 112 spoofable: 013 classification:1415 label: "Potential Defense Evasion Activity Via Emoji Usage In CommandLine - 4"16 behavior : "windows:audit"17 remediation: false1819scope:20 type: ParentProcessId21 expression: evt.Parsed.ParentProcessId2223