Florian Roth
|
b558f5914e
|
Added reference to Tom Ueltschie's slides
|
2017-11-09 18:30:50 +01:00 |
|
Florian Roth
|
781db7404e
|
Updated Adwind RAT rule
|
2017-11-09 18:28:27 +01:00 |
|
Florian Roth
|
970f01f9f2
|
Renamed file for consistency
|
2017-11-09 15:43:32 +01:00 |
|
Florian Roth
|
a042105aa1
|
Rule: Adwind RAT / JRAT javaw.exe process starts in AppData folder
|
2017-11-09 15:43:32 +01:00 |
|
Thomas Patzke
|
5035c9c490
|
Converted Windows 4688-only rules into 4688 and Sysmon/1 collections
|
2017-11-01 22:12:14 +01:00 |
|
Thomas Patzke
|
986c9ff9b7
|
Added field names to first rules
|
2017-09-12 23:54:04 +02:00 |
|
Florian Roth
|
950a00f33e
|
Updated Petya rule
|
2017-06-28 12:52:58 +02:00 |
|
Florian Roth
|
ece1d7e3a8
|
Added perfc.dat keyword to NotPetya rule
|
2017-06-28 10:35:42 +02:00 |
|
Florian Roth
|
a3e0e37163
|
NotPetya Title Fixed
|
2017-06-28 09:12:39 +02:00 |
|
Florian Roth
|
8c437de970
|
NotPetya Sigma Rule for Sysmon Events
|
2017-06-28 09:09:12 +02:00 |
|
Florian Roth
|
8f525d2f01
|
Wannacry Rules Reorg and Renaming
|
2017-06-28 09:08:53 +02:00 |
|