Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Florian Roth
|
e0009bfb4a
|
fix: merged duplicate rules
|
2019-10-01 16:14:38 +02:00 |
|
Thomas Patzke
|
3ef930b094
|
Escaped '\*' to '\\*' where required
|
2019-02-03 00:24:57 +01:00 |
|
Ensar Şamil
|
dec7568d4c
|
Rule simplification
Two selection fields are reduced to one. HKCU and HKLM registry value changes are considered, thus wildcards are added. No change at details.
|
2018-09-28 10:58:50 +03:00 |
|
Thomas Patzke
|
87e39b8768
|
Fixed rules
|
2018-08-26 22:30:47 +02:00 |
|
yt0ng
|
df9f6688eb
|
Added Deskop Location, RunOnce and ATTCK
Added C:\Users\tst01\Desktop\unprotected.vbs as seen by FIN7
|
2018-08-25 17:32:34 +02:00 |
|
Florian Roth
|
deea224421
|
Rule: New RUN Key Pointing to Suspicious Folder
|
2017-10-17 16:19:56 +02:00 |
|