Florian Roth
|
abb01cc264
|
Rule: PowerShell credential prompt
|
2017-04-09 10:22:04 +02:00 |
|
Florian Roth
|
fa37f5afcf
|
Rules: PowerShell Downgrade Attacks
|
2017-03-22 11:17:46 +01:00 |
|
Florian Roth
|
055992eb05
|
Bugfix: PowerShell rules log source inconstency
|
2017-03-21 10:22:13 +01:00 |
|
Florian Roth
|
a0047f7c67
|
Sysmon as 'service' of product 'windows'
|
2017-03-13 09:23:08 +01:00 |
|
Florian Roth
|
de689c32b5
|
Suspicious PowerShell Invocation
|
2017-03-12 17:06:53 +01:00 |
|
Florian Roth
|
294df21c56
|
Added expression
|
2017-03-05 22:45:54 +01:00 |
|
Florian Roth
|
7fae49b183
|
More PowerShell rules
|
2017-03-05 15:01:51 +01:00 |
|
Florian Roth
|
1e1cf9cb9e
|
PowerShell Rules Revision
|
2017-03-05 14:14:31 +01:00 |
|
Omer Yampel
|
97b4078d01
|
Update powershell_malicious_commandlets.yml
Added https://github.com/putterpanda/mimikittenz reference
|
2017-03-04 20:26:39 -05:00 |
|
Florian Roth
|
d397ee9f68
|
First PowerShell Ruleset
|
2017-03-05 01:47:25 +01:00 |
|