Yugoslavskiy Daniil
|
42c4079ed8
|
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
|
2020-08-25 01:09:17 +02:00 |
|
Florian Roth
|
d42e87edd7
|
fix: fixed casing and long rule titles
|
2020-01-30 17:26:09 +01:00 |
|
Florian Roth
|
e79e99c4aa
|
fix: fixed missing date fields in remaining files
|
2020-01-30 16:07:37 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Thomas Patzke
|
765fe9dcd9
|
Further improved Windows user creation rule
* Decreased level
* Fixed field names
* Added false positive possibility
|
2019-04-21 23:54:18 +02:00 |
|
Thomas Patzke
|
80f45349ed
|
Modified rule
* Adjusted ATT&CK tagging
* Set status
|
2019-04-21 00:14:57 +02:00 |
|
patrick
|
8609fc7ece
|
New Sigma rule detecting local user creation
|
2019-04-18 19:59:43 +02:00 |
|