Florian Roth
|
7bef822da7
|
rule: minor improvement to susp ps enc cmd
|
2019-09-04 16:31:49 +02:00 |
|
Florian Roth
|
0657f29c99
|
Rule: reworked win_susp_powershell_enc_cmd
|
2019-07-30 14:36:30 +02:00 |
|
Florian Roth
|
03d8184990
|
Rule: Extended PowerShell Susp Cmdline Enc Commands
|
2019-04-20 09:38:41 +02:00 |
|
Karneades
|
75d36165fc
|
Remove non-generic falsepositives
There are tons of FPs for that... :)
|
2019-04-11 12:55:24 +02:00 |
|
Karneades
|
51e65be98b
|
Remove loose wildcard filter in powershell encoded cmd rule
|
2019-04-11 12:53:12 +02:00 |
|
mikhail
|
40241c1fdf
|
Fix 4 rules
|
2019-03-06 01:56:05 +03:00 |
|
Thomas Patzke
|
7602309138
|
Increased indentation to 4
* Converted (to generic sigma) rules
* Converter outputs by default with indentation 4
|
2019-03-02 00:14:20 +01:00 |
|
Thomas Patzke
|
c922f7d73f
|
Merge branch 'master' into project-1
|
2019-02-26 00:24:46 +01:00 |
|
Thomas Patzke
|
96eb460944
|
Converted Sysmon/1 and Security/4688 to generic process creation rules
|
2019-01-16 23:36:31 +01:00 |
|