Commit Graph

2030 Commits

Author SHA1 Message Date
feedb
54b75b73b2 [OSCD] process_creation_msdeploy 2020-10-18 17:37:14 +03:00
feedb
2b731300fb [OSCD] LOLBIN dotnet.exe exec dll and execute unsigned code
=/
2020-10-18 17:13:41 +03:00
feedb
744d27d892 [OSCD] LOLBIN dotnet.exe exec dll and execute unsigned code 2020-10-18 17:08:52 +03:00
feedb
e7c9ead469 [OSCD] LOLBIN dotnet.exe exec dll and execute unsigned code 2020-10-18 17:06:09 +03:00
feedb
fabf2a03fe Delete win_mshta_invoke_html.yml 2020-10-18 15:29:43 +03:00
feedb
468fd40dda Update win_mshta_invoke_html.yml 2020-10-18 15:23:44 +03:00
feedb
6b39f7bb6e Update win_mshta_invoke_html.yml 2020-10-18 15:19:58 +03:00
feedb
ad11fc7b0e Update win_mshta_invoke_html.yml 2020-10-18 15:14:13 +03:00
feedb
5b35991cdd Update win_mshta_invoke_html.yml 2020-10-18 15:05:01 +03:00
feedb
91692e49cd Update win_mshta_invoke_html.yml 2020-10-18 15:02:03 +03:00
feedb
3806196071 Create win_mshta_invoke_html.yml 2020-10-18 14:57:22 +03:00
yugoslavskiy
3f1c94837b
Rename process_creation_susp_openwith_execution.yml to process_creation_susp_openwith.yml 2019-11-04 20:38:44 +03:00
yugoslavskiy
54e9be9cd0
Rename process_creation_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher.yml 2019-11-04 20:38:24 +03:00
yugoslavskiy
999126446b
Rename win_susp_psr_capture_screenshots.yml to process_creation_susp_psr_capture_screenshots.yml 2019-11-04 20:37:16 +03:00
yugoslavskiy
85cd989b6f
Rename win_susp_openwith_execution.yml to process_creation_susp_openwith_execution.yml 2019-11-04 20:36:58 +03:00
yugoslavskiy
8d0923de2d
Rename win_susp_odbcconf.yml to process_creation_susp_odbcconf.yml 2019-11-04 20:36:46 +03:00
yugoslavskiy
de098ff5b7
Rename win_susp_msoffice.yml to process_creation_susp_msoffice.yml 2019-11-04 20:36:21 +03:00
yugoslavskiy
9c19d1b58c
Rename win_susp_dxcap.yml to process_creation_susp_dxcap.yml 2019-11-04 20:36:07 +03:00
yugoslavskiy
66eba43a8d
Rename win_susp_dnx.yml to process_creation_susp_dnx.yml 2019-11-04 20:35:53 +03:00
yugoslavskiy
d18314b6b2
Rename win_susp_devtoolslauncher_execution.yml to process_creation_susp_devtoolslauncher_execution.yml 2019-11-04 20:35:43 +03:00
yugoslavskiy
49bc6ada25
Rename win_susp_cdb.yml to process_creation_susp_cdb.yml 2019-11-04 20:35:28 +03:00
yugoslavskiy
95412e5f30
Rename win_susp_bginfo.yml to process_creation_susp_bginfo.yml 2019-11-04 20:35:11 +03:00
yugoslavskiy
19396fd274
Update sysmon_webshell_creation_detect.yml 2019-11-04 19:23:52 +03:00
yugoslavskiy
9371e533c3
Update win_susp_openwith_execution.yml 2019-11-04 19:05:23 +03:00
yugoslavskiy
e6a39f1061
Update win_susp_odbcconf.yml 2019-11-04 19:01:30 +03:00
yugoslavskiy
c18fa0940d
Update win_susp_msoffice.yml 2019-11-04 18:44:07 +03:00
yugoslavskiy
bd0ebf0604
Update win_susp_dxcap.yml 2019-11-04 18:43:42 +03:00
yugoslavskiy
df07291e53
Update win_susp_cdb.yml 2019-11-04 18:43:03 +03:00
yugoslavskiy
a66539c771
Update win_susp_msoffice.yml 2019-11-04 18:42:26 +03:00
yugoslavskiy
56b7402e62
Update win_susp_dxcap.yml 2019-11-04 18:38:37 +03:00
yugoslavskiy
a9fdfee5c2
Update win_susp_dnx.yml 2019-11-04 18:34:25 +03:00
yugoslavskiy
dc23e566a0
Update win_susp_devtoolslauncher_execution.yml 2019-11-04 18:30:04 +03:00
yugoslavskiy
989d75033a
Update win_susp_cdb.yml 2019-11-04 18:25:30 +03:00
yugoslavskiy
43c20d203d
Update and rename win_susp_capture_screenshots.yml to win_susp_psr_capture_screenshots.yml 2019-11-04 18:16:39 +03:00
yugoslavskiy
a800093aaf
Update win_susp_bginfo.yml 2019-11-04 18:14:44 +03:00
yugoslavskiy
8a35a51211
Update lnx_auditd_web_rce.yml 2019-11-04 18:08:17 +03:00
root
717e40e8ed modified win_susp_dxcap.yml 2019-10-26 20:27:32 +02:00
root
9bf0150100 modified win_susp_dnx.yml 2019-10-26 20:20:21 +02:00
root
3b70f2edd6 modified win_susp_dnx.yml 2019-10-26 20:16:40 +02:00
root
3528afeef7 modified win_susp_dnx.yml 2019-10-26 20:13:53 +02:00
root
1dca0456ee modified win_susp_dxcap.yml 2019-10-26 20:09:25 +02:00
root
cbe0d73ce8 add win_susp_dxcap.yml 2019-10-26 20:06:02 +02:00
root
aaf63d2238 add win_susp_dxcap.yml 2019-10-26 20:02:25 +02:00
root
0616c2c39d add win_susp_dnx.yml 2019-10-26 19:58:45 +02:00
root
ee21888e67 add win_susp_cdb.yml 2019-10-26 19:49:45 +02:00
root
844d55c781 add win_susp_bginfo.yml 2019-10-26 08:18:37 +02:00
root
5bb5938e86 add win_susp_bginfo.yml 2019-10-26 08:16:08 +02:00
root
01c4c7cdbd modifed win_susp_msoffice.yml 2019-10-26 08:11:09 +02:00
root
bea2daac45 modifed win_susp_msoffice.yml 2019-10-26 07:55:44 +02:00
root
fc7f8ecea3 add win_susp_msoffice.yml 2019-10-26 07:48:38 +02:00