Jonhnathan
|
d3c6d9df31
|
Update win_mal_ryuk.yml
|
2020-10-27 22:21:16 -03:00 |
|
Jonhnathan
|
98c7639db7
|
Update mal_azorult_reg.yml
|
2020-10-27 22:19:04 -03:00 |
|
Jonhnathan
|
8f4d6f802b
|
Update mal_azorult_reg.yml
|
2020-10-27 22:18:41 -03:00 |
|
Jonhnathan
|
bfb50a3d42
|
Update sysmon_susp_office_dsparse_dll_load.yml
|
2020-10-27 22:13:02 -03:00 |
|
Jonhnathan
|
3477866451
|
Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml
|
2020-10-27 22:10:17 -03:00 |
|
Jonhnathan
|
9fd203e2a3
|
Update mal_azorult_reg.yml
|
2020-10-27 22:07:45 -03:00 |
|
Jonhnathan
|
ebb84486f5
|
Update sysmon_susp_adsi_cache_usage.yml
|
2020-10-27 22:04:31 -03:00 |
|
Jonhnathan
|
182b12614b
|
Update sysmon_quarkspw_filedump.yml
|
2020-10-27 22:02:47 -03:00 |
|
Jonhnathan
|
dde5b46726
|
Update win_susp_sam_dump.yml
|
2020-10-27 22:01:31 -03:00 |
|
Jonhnathan
|
61ccdc598d
|
Update win_susp_local_anon_logon_created.yml
|
2020-10-27 22:00:42 -03:00 |
|
Jonhnathan
|
3eea825898
|
Update win_net_ntlm_downgrade.yml
|
2020-10-27 21:59:49 -03:00 |
|
Jonhnathan
|
53ff19f167
|
Update win_mmc20_lateral_movement.yml
|
2020-10-27 21:55:17 -03:00 |
|
Jonhnathan
|
3f23aa56c0
|
Revert "Revert "Changed the rule to download only and not the copy""
This reverts commit 17e7eee3a6 .
|
2020-10-16 11:05:51 -03:00 |
|
Jonhnathan
|
0734274dfa
|
Revert "Revert "Create win_susp_replace_lolbin.yml""
This reverts commit fdd9234acc .
|
2020-10-16 11:05:40 -03:00 |
|
Jonhnathan
|
9a5c166bb2
|
Fix filter
|
2020-10-16 07:35:59 -03:00 |
|
Jonhnathan
|
2332e42e4c
|
Update win_susp_copy_lateral_movement.yml
|
2020-10-15 21:01:23 -03:00 |
|
Jonhnathan
|
d4603d196b
|
Update win_susp_adfind.yml
|
2020-10-15 21:00:15 -03:00 |
|
Jonhnathan
|
fc6c727c70
|
Update powershell_malicious_commandlets.yml
|
2020-10-15 20:59:27 -03:00 |
|
Jonhnathan
|
1584ddf918
|
Update sysmon_susp_service_installed.yml
|
2020-10-15 20:50:42 -03:00 |
|
Jonhnathan
|
f4872118a2
|
Update win_powershell_dll_execution.yml
|
2020-10-15 20:38:55 -03:00 |
|
Jonhnathan
|
3566dd1594
|
Fix
|
2020-10-15 20:35:50 -03:00 |
|
Jonhnathan
|
44c909a4a4
|
Update win_apt_mustangpanda.yml
|
2020-10-15 20:33:00 -03:00 |
|
Jonhnathan
|
5fc348fd45
|
Fix
|
2020-10-15 20:32:16 -03:00 |
|
Jonhnathan
|
37ee747dfe
|
Update win_apt_chafer_mar18.yml
|
2020-10-15 20:30:52 -03:00 |
|
Jonhnathan
|
1fac65dad0
|
Fix
|
2020-10-15 20:29:02 -03:00 |
|
Jonhnathan
|
0dfacd1f63
|
Fix
|
2020-10-15 20:27:10 -03:00 |
|
Jonhnathan
|
9795c95a9b
|
Update av_webshell.yml
|
2020-10-15 20:25:34 -03:00 |
|
Jonhnathan
|
345c3c6451
|
Fix
|
2020-10-15 20:24:31 -03:00 |
|
Jonhnathan
|
86ade194a4
|
Fix
|
2020-10-15 20:22:56 -03:00 |
|
Jonhnathan
|
0666d21b06
|
Update win_dcsync.yml
|
2020-10-15 20:19:06 -03:00 |
|
Jonhnathan
|
d7eda3fe7e
|
Update sysmon_wmi_susp_scripting.yml
|
2020-10-15 20:15:22 -03:00 |
|
Jonhnathan
|
92aaeca075
|
Update sysmon_susp_powershell_rundll32.yml
|
2020-10-15 20:14:23 -03:00 |
|
Jonhnathan
|
26b36086c7
|
Update sysmon_cmstp_execution.yml
|
2020-10-15 20:13:39 -03:00 |
|
Jonhnathan
|
df81f5180d
|
Update sysmon_cactustorch.yml
|
2020-10-15 20:12:54 -03:00 |
|
Jonhnathan
|
457217bfc0
|
Update sysmon_win_reg_persistence.yml
|
2020-10-15 20:11:52 -03:00 |
|
Jonhnathan
|
229e57777a
|
Update sysmon_win_reg_persistence.yml
|
2020-10-15 20:11:37 -03:00 |
|
Jonhnathan
|
8a52610bf8
|
Update sysmon_uac_bypass_eventvwr.yml
|
2020-10-15 20:11:11 -03:00 |
|
Jonhnathan
|
6ea18efdaf
|
Update sysmon_sysinternals_eula_accepted.yml
|
2020-10-15 20:10:44 -03:00 |
|
Jonhnathan
|
7dfb8f0e99
|
Update sysmon_suspicious_keyboard_layout_load.yml
|
2020-10-15 20:10:21 -03:00 |
|
Jonhnathan
|
9c434eaf04
|
Update sysmon_susp_service_installed.yml
|
2020-10-15 20:10:06 -03:00 |
|
Jonhnathan
|
33ed01e285
|
Update sysmon_susp_run_key_img_folder.yml
|
2020-10-15 20:09:42 -03:00 |
|
Jonhnathan
|
45466cf95d
|
Update sysmon_susp_reg_persist_explorer_run.yml
|
2020-10-15 20:08:47 -03:00 |
|
Jonhnathan
|
b55b78c42d
|
Update sysmon_susp_lsass_dll_load.yml
|
2020-10-15 20:08:12 -03:00 |
|
Jonhnathan
|
17ade8e5f5
|
Update sysmon_susp_download_run_key.yml
|
2020-10-15 20:07:53 -03:00 |
|
Jonhnathan
|
6fc6409c7f
|
Update sysmon_stickykey_like_backdoor.yml
|
2020-10-15 20:07:11 -03:00 |
|
Jonhnathan
|
03ea1375e2
|
Update sysmon_registry_persistence_search_order.yml
|
2020-10-15 20:05:46 -03:00 |
|
Jonhnathan
|
f101d661f0
|
Update sysmon_reg_office_security.yml
|
2020-10-15 20:05:11 -03:00 |
|
Jonhnathan
|
176b7ce08f
|
Update sysmon_rdp_settings_hijack.yml
|
2020-10-15 20:04:57 -03:00 |
|
Jonhnathan
|
4c9cf8b759
|
Update sysmon_new_dll_added_to_appinit_dlls_registry_key.yml
|
2020-10-15 20:04:31 -03:00 |
|
Jonhnathan
|
51eefbae0c
|
Update sysmon_logon_scripts_userinitmprlogonscript_reg.yml
|
2020-10-15 20:04:05 -03:00 |
|
Jonhnathan
|
143e6512ad
|
Update sysmon_dns_serverlevelplugindll.yml
|
2020-10-15 20:03:42 -03:00 |
|
Jonhnathan
|
c4a44e2376
|
Update sysmon_dns_serverlevelplugindll.yml
|
2020-10-15 20:03:29 -03:00 |
|
Jonhnathan
|
bdca2febe9
|
Update sysmon_dhcp_calloutdll.yml
|
2020-10-15 20:02:58 -03:00 |
|
Jonhnathan
|
337e26a034
|
Update sysmon_cmstp_execution.yml
|
2020-10-15 20:02:37 -03:00 |
|
Jonhnathan
|
4adf092a25
|
Update win_workflow_compiler.yml
|
2020-10-15 20:00:57 -03:00 |
|
Jonhnathan
|
eb9bac761f
|
Update win_wmi_spwns_powershell.yml
|
2020-10-15 20:00:44 -03:00 |
|
Jonhnathan
|
b2e1b857ae
|
Update win_wmi_backdoor_exchange_transport_agent.yml
|
2020-10-15 20:00:27 -03:00 |
|
Jonhnathan
|
86ad1f45f5
|
Update win_win10_sched_task_0day.yml
|
2020-10-15 20:00:13 -03:00 |
|
Jonhnathan
|
630e92f3c2
|
Update win_webshell_spawn.yml
|
2020-10-15 19:59:59 -03:00 |
|
Jonhnathan
|
138b8fed06
|
Update win_webshell_recon_detection.yml
|
2020-10-15 19:59:36 -03:00 |
|
Jonhnathan
|
e402356e82
|
Update win_webshell_detection.yml
|
2020-10-15 19:58:37 -03:00 |
|
Jonhnathan
|
2d9233d418
|
Update win_vul_java_remote_debugging.yml
|
2020-10-15 19:57:43 -03:00 |
|
Jonhnathan
|
d9afa1aec6
|
Update win_termserv_proc_spawn.yml
|
2020-10-15 19:57:05 -03:00 |
|
Jonhnathan
|
737fbd1619
|
Update win_system_exe_anomaly.yml
|
2020-10-15 19:55:57 -03:00 |
|
Jonhnathan
|
434c6257f0
|
Update win_susp_wmi_execution.yml
|
2020-10-15 19:52:25 -03:00 |
|
Jonhnathan
|
7b9ec4709f
|
Update win_susp_whoami.yml
|
2020-10-15 19:51:55 -03:00 |
|
Jonhnathan
|
d09dd70695
|
Update win_susp_userinit_child.yml
|
2020-10-15 19:51:42 -03:00 |
|
Jonhnathan
|
ad8620f729
|
Update win_susp_tscon_rdp_redirect.yml
|
2020-10-15 19:51:05 -03:00 |
|
Jonhnathan
|
c38ccefc21
|
Update win_susp_tscon_localsystem.yml
|
2020-10-15 19:50:14 -03:00 |
|
Jonhnathan
|
9d8116c486
|
Update win_susp_taskmgr_parent.yml
|
2020-10-15 19:50:04 -03:00 |
|
Jonhnathan
|
dde03e760b
|
Update win_susp_taskmgr_localsystem.yml
|
2020-10-15 19:49:47 -03:00 |
|
Jonhnathan
|
4543e18e4e
|
Update win_susp_sysvol_access.yml
|
2020-10-15 19:49:31 -03:00 |
|
Jonhnathan
|
08a018a2ee
|
Update win_susp_sysprep_appdata.yml
|
2020-10-15 19:49:12 -03:00 |
|
Jonhnathan
|
4c9124952e
|
Update win_susp_svchost.yml
|
2020-10-15 19:47:47 -03:00 |
|
Jonhnathan
|
5c7bc4c48a
|
Update win_susp_schtask_creation.yml
|
2020-10-15 19:47:15 -03:00 |
|
Jonhnathan
|
d3f0d25ffb
|
Update win_susp_rundll32_by_ordinal.yml
|
2020-10-15 19:46:54 -03:00 |
|
Jonhnathan
|
8d471775e0
|
Update win_susp_regsvr32_anomalies.yml
|
2020-10-15 19:45:08 -03:00 |
|
Jonhnathan
|
cc338507c9
|
Update win_susp_ps_appdata.yml
|
2020-10-15 19:43:37 -03:00 |
|
Jonhnathan
|
91fb5cdcd0
|
Update win_susp_prog_location_process_starts.yml
|
2020-10-15 19:43:19 -03:00 |
|
Jonhnathan
|
253014ee68
|
Update win_susp_procdump.yml
|
2020-10-15 19:42:48 -03:00 |
|
Jonhnathan
|
f614ac658f
|
Update win_susp_powershell_parent_combo.yml
|
2020-10-15 19:42:20 -03:00 |
|
Jonhnathan
|
1feba3a12c
|
Update win_susp_powershell_hidden_b64_cmd.yml
|
2020-10-15 19:40:23 -03:00 |
|
Jonhnathan
|
7df7d7f48b
|
Update win_susp_powershell_enc_cmd.yml
|
2020-10-15 19:39:11 -03:00 |
|
Jonhnathan
|
610ae5ddd7
|
Update win_susp_powershell_enc_cmd.yml
|
2020-10-15 19:38:47 -03:00 |
|
Jonhnathan
|
4485436957
|
Update win_susp_powershell_empire_uac_bypass.yml
|
2020-10-15 19:34:18 -03:00 |
|
Jonhnathan
|
90d20094ac
|
Update win_susp_ping_hex_ip.yml
|
2020-10-15 19:34:00 -03:00 |
|
Jonhnathan
|
6bb9f1b3c9
|
Update win_susp_outlook_temp.yml
|
2020-10-15 19:33:45 -03:00 |
|
Jonhnathan
|
60f867b989
|
Update win_susp_outlook.yml
|
2020-10-15 19:33:33 -03:00 |
|
Jonhnathan
|
98ebb4965d
|
Update win_susp_ntdsutil.yml
|
2020-10-15 19:33:10 -03:00 |
|
Jonhnathan
|
ec9f9fd929
|
Update win_susp_net_execution.yml
|
2020-10-15 19:32:29 -03:00 |
|
Jonhnathan
|
6cd49220ad
|
Update win_susp_msiexec_web_install.yml
|
2020-10-15 19:31:44 -03:00 |
|
Jonhnathan
|
e8477c8afa
|
Update win_susp_msiexec_cwd.yml
|
2020-10-15 19:31:27 -03:00 |
|
Jonhnathan
|
0e1ae89a5c
|
Update win_susp_iss_module_install.yml
|
2020-10-15 19:30:56 -03:00 |
|
Jonhnathan
|
cd6149bcc3
|
Update win_susp_gup.yml
|
2020-10-15 19:30:43 -03:00 |
|
Jonhnathan
|
985f56c0e9
|
Update win_susp_findstr_lnk.yml
|
2020-10-15 19:30:21 -03:00 |
|
Jonhnathan
|
ab7bdf6af5
|
Update win_susp_file_characteristics.yml
|
2020-10-15 19:30:07 -03:00 |
|
Jonhnathan
|
ee8edb1e15
|
Update win_susp_execution_path_webserver.yml
|
2020-10-15 19:29:46 -03:00 |
|
Jonhnathan
|
fedc5b88e0
|
Update win_susp_execution_path.yml
|
2020-10-15 19:29:05 -03:00 |
|
Jonhnathan
|
9ef41cbc77
|
Update win_susp_exec_folder.yml
|
2020-10-15 19:28:23 -03:00 |
|
Jonhnathan
|
f33f7010fa
|
Update win_susp_double_extension.yml
|
2020-10-15 19:27:17 -03:00 |
|
Jonhnathan
|
92966098b9
|
Update win_susp_csc_folder.yml
|
2020-10-15 19:25:38 -03:00 |
|
Jonhnathan
|
bc042b5764
|
Update win_susp_csc.yml
|
2020-10-15 19:24:30 -03:00 |
|
Jonhnathan
|
5f4df56247
|
Update win_susp_crackmapexec_execution.yml
|
2020-10-15 19:23:58 -03:00 |
|
Jonhnathan
|
30601ab134
|
Update win_susp_copy_lateral_movement.yml
|
2020-10-15 19:22:49 -03:00 |
|
Jonhnathan
|
fbe27b3b31
|
Update win_susp_control_dll_load.yml
|
2020-10-15 19:21:41 -03:00 |
|
Jonhnathan
|
932dabf7ea
|
Update win_susp_comsvcs_procdump.yml
|
2020-10-15 19:21:11 -03:00 |
|
Jonhnathan
|
e33694bd98
|
Update win_susp_compression_params.yml
|
2020-10-15 19:19:48 -03:00 |
|
Jonhnathan
|
ce8d649275
|
Update win_susp_cli_escape.yml
|
2020-10-15 18:30:46 -03:00 |
|
Jonhnathan
|
1752c614d1
|
Update win_susp_certutil_encode.yml
|
2020-10-15 18:30:25 -03:00 |
|
Jonhnathan
|
04125cc4c0
|
Update win_susp_certutil_command.yml
|
2020-10-15 18:29:56 -03:00 |
|
Jonhnathan
|
4a3bb4b963
|
Update win_susp_calc.yml
|
2020-10-15 18:29:12 -03:00 |
|
Jonhnathan
|
9152afda20
|
Update win_susp_bcdedit.yml
|
2020-10-15 18:28:42 -03:00 |
|
Jonhnathan
|
79951ce104
|
Update win_susp_adfind.yml
|
2020-10-15 18:26:44 -03:00 |
|
Jonhnathan
|
544f015f76
|
Update win_spn_enum.yml
|
2020-10-15 18:26:26 -03:00 |
|
Jonhnathan
|
b9dedd0d07
|
Update win_shell_spawn_susp_program.yml
|
2020-10-15 18:25:59 -03:00 |
|
Jonhnathan
|
38f460718d
|
Update win_sdbinst_shim_persistence.yml
|
2020-10-15 18:25:12 -03:00 |
|
Jonhnathan
|
9751cac1a2
|
Update win_renamed_psexec.yml
|
2020-10-15 18:24:48 -03:00 |
|
Jonhnathan
|
081f5a90fe
|
Update win_renamed_procdump.yml
|
2020-10-15 18:24:32 -03:00 |
|
Jonhnathan
|
57445969f1
|
Update win_renamed_powershell.yml
|
2020-10-15 18:24:16 -03:00 |
|
Jonhnathan
|
aac35341f5
|
Update win_renamed_paexec.yml
|
2020-10-15 18:24:00 -03:00 |
|
Jonhnathan
|
72de132624
|
Update win_process_creation_bitsadmin_download.yml
|
2020-10-15 18:23:29 -03:00 |
|
Jonhnathan
|
64c63c8d38
|
Update win_proc_wrong_parent.yml
|
2020-10-15 18:23:03 -03:00 |
|
Jonhnathan
|
1f76c1f897
|
Update win_powersploit_empire_schtasks.yml
|
2020-10-15 18:22:04 -03:00 |
|
Jonhnathan
|
c47fb4708f
|
Update win_powershell_download.yml
|
2020-10-15 18:21:32 -03:00 |
|
Jonhnathan
|
cb57e08bc0
|
Update win_powershell_dll_execution.yml
|
2020-10-15 18:21:05 -03:00 |
|
Jonhnathan
|
98d6b37af4
|
Update win_powershell_b64_shellcode.yml
|
2020-10-15 18:20:29 -03:00 |
|
Jonhnathan
|
5263212b49
|
Update win_powershell_amsi_bypass.yml
|
2020-10-15 18:20:08 -03:00 |
|
Jonhnathan
|
fec14fa405
|
Update win_plugx_susp_exe_locations.yml
|
2020-10-15 18:19:36 -03:00 |
|
Jonhnathan
|
aa728e91da
|
Update win_office_spawn_exe_from_users_directory.yml
|
2020-10-15 18:13:29 -03:00 |
|
Jonhnathan
|
58f6fd4e4f
|
Update win_office_shell.yml
|
2020-10-15 18:13:10 -03:00 |
|
Jonhnathan
|
e7f25a61bf
|
Update win_netsh_fw_add_susp_image.yml
|
2020-10-15 18:12:03 -03:00 |
|
Jonhnathan
|
7ce7646e4a
|
Update win_netsh_fw_add.yml
|
2020-10-15 18:11:17 -03:00 |
|
Jonhnathan
|
143f9d00c5
|
Update win_mshta_spawn_shell.yml
|
2020-10-15 18:10:38 -03:00 |
|
Jonhnathan
|
5a0c7f6d11
|
Update win_mmc_spawn_shell.yml
|
2020-10-15 18:09:27 -03:00 |
|
Jonhnathan
|
e0ff1c09c9
|
Update win_mmc_spawn_shell.yml
|
2020-10-15 18:08:49 -03:00 |
|
Jonhnathan
|
247a85e04a
|
Update win_mavinject_proc_inj.yml
|
2020-10-15 18:06:51 -03:00 |
|
Jonhnathan
|
3e7c770ef9
|
Update win_malware_wannacry.yml
|
2020-10-15 18:06:22 -03:00 |
|
Jonhnathan
|
0f6edaf3f4
|
Update win_malware_trickbot_recon_activity.yml
|
2020-10-15 18:05:41 -03:00 |
|
Jonhnathan
|
11380518d2
|
Update win_malware_script_dropper.yml
|
2020-10-15 18:04:48 -03:00 |
|
Jonhnathan
|
3152b8f174
|
Update win_malware_qbot.yml
|
2020-10-15 18:02:35 -03:00 |
|
Jonhnathan
|
da7648f154
|
Update win_malware_notpetya.yml
|
2020-10-15 18:02:08 -03:00 |
|
Jonhnathan
|
99451424f6
|
Update win_malware_formbook.yml
|
2020-10-15 18:01:21 -03:00 |
|
Jonhnathan
|
d962e5b844
|
Update win_malware_emotet.yml
|
2020-10-15 18:01:00 -03:00 |
|
Jonhnathan
|
035cd43e58
|
Update win_malware_dtrack.yml
|
2020-10-15 18:00:12 -03:00 |
|
Jonhnathan
|
885afd7b60
|
Update win_malware_dridex.yml
|
2020-10-15 17:59:57 -03:00 |
|
Jonhnathan
|
483748c2c3
|
Update win_mal_adwind.yml
|
2020-10-15 17:59:24 -03:00 |
|
Jonhnathan
|
3ca2988828
|
Update win_mal_adwind.yml
|
2020-10-15 17:59:04 -03:00 |
|
Jonhnathan
|
cc31cf6196
|
Update win_lethalhta.yml
|
2020-10-15 17:58:14 -03:00 |
|
Jonhnathan
|
326122c798
|
Update win_install_reg_debugger_backdoor.yml
|
2020-10-15 17:57:43 -03:00 |
|
Jonhnathan
|
7c6f6adbcc
|
Update win_impacket_lateralization.yml
|
2020-10-15 17:56:15 -03:00 |
|
Jonhnathan
|
9e99832b76
|
Update win_hwp_exploits.yml
|
2020-10-15 17:55:04 -03:00 |
|
Jonhnathan
|
d1e447a3fd
|
Update win_hktl_createminidump.yml
|
2020-10-15 17:54:42 -03:00 |
|
Jonhnathan
|
3cde51f97b
|
Update win_hack_rubeus.yml
|
2020-10-15 17:54:20 -03:00 |
|
Jonhnathan
|
0b52f14639
|
Update win_hack_koadic.yml
|
2020-10-15 17:53:44 -03:00 |
|
Jonhnathan
|
f44eb6345c
|
Update win_grabbing_sensitive_hives_via_reg.yml
|
2020-10-15 17:53:20 -03:00 |
|
Jonhnathan
|
61a2f105c2
|
Update win_exploit_cve_2020_10189.yml
|
2020-10-15 17:52:53 -03:00 |
|
Jonhnathan
|
febe489c99
|
Update win_exploit_cve_2019_1388.yml
|
2020-10-15 17:52:40 -03:00 |
|
Jonhnathan
|
d7b63b8245
|
Update win_exploit_cve_2019_1378.yml
|
2020-10-15 17:51:58 -03:00 |
|
Jonhnathan
|
2b8f770b90
|
Update win_exploit_cve_2017_8759.yml
|
2020-10-15 17:51:34 -03:00 |
|
Jonhnathan
|
e5506f4de1
|
Update win_exploit_cve_2017_11882.yml
|
2020-10-15 17:51:20 -03:00 |
|
Jonhnathan
|
e163bb18ef
|
Update win_exploit_cve_2017_0261.yml
|
2020-10-15 17:51:09 -03:00 |
|
Jonhnathan
|
890e256305
|
Update win_exploit_cve_2015_1641.yml
|
2020-10-15 17:50:55 -03:00 |
|
Jonhnathan
|
a3f59d6f03
|
Update win_dnscat2_powershell_implementation.yml
|
2020-10-15 17:49:36 -03:00 |
|
Jonhnathan
|
9f467f66e6
|
Update win_dns_exfiltration_tools_execution.yml
|
2020-10-15 17:49:18 -03:00 |
|
Jonhnathan
|
1f7f0956af
|
Update win_crime_fireball.yml
|
2020-10-15 17:48:37 -03:00 |
|
Jonhnathan
|
9d2ae693fc
|
Update win_control_panel_item.yml
|
2020-10-15 17:47:25 -03:00 |
|
Jonhnathan
|
1ea8adea31
|
Update win_cmdkey_recon.yml
|
2020-10-15 17:46:14 -03:00 |
|
Jonhnathan
|
f995f9fa1d
|
Update win_bypass_squiblytwo.yml
Changed selection a bit
|
2020-10-15 17:44:51 -03:00 |
|
Jonhnathan
|
63dc8ce837
|
Update win_attrib_hiding_files.yml
|
2020-10-15 17:41:44 -03:00 |
|
Jonhnathan
|
afc52e5da5
|
Update win_apt_zxshell.yml
|
2020-10-15 17:40:07 -03:00 |
|
Jonhnathan
|
ae95b5e998
|
Update win_apt_wocao.yml
|
2020-10-15 17:38:05 -03:00 |
|
Jonhnathan
|
5e3b9dc8ba
|
Update win_apt_unidentified_nov_18.yml
|
2020-10-15 17:36:20 -03:00 |
|
Jonhnathan
|
126fc47101
|
Update win_apt_tropictrooper.yml
|
2020-10-15 17:35:41 -03:00 |
|
Jonhnathan
|
3b78c473c8
|
Update win_apt_slingshot.yml
|
2020-10-15 17:35:05 -03:00 |
|
Jonhnathan
|
c547011499
|
Update win_apt_mustangpanda.yml
|
2020-10-15 17:33:44 -03:00 |
|
Jonhnathan
|
82fbfed2c2
|
Update win_apt_mustangpanda.yml
|
2020-10-15 17:33:02 -03:00 |
|
Jonhnathan
|
a06114d611
|
Update win_apt_lazarus_session_highjack.yml
|
2020-10-15 17:31:50 -03:00 |
|
Jonhnathan
|
01bf24b4fc
|
Update win_apt_judgement_panda_gtr19.yml
|
2020-10-15 17:31:09 -03:00 |
|
Jonhnathan
|
7f5c75ab3e
|
Update win_apt_hurricane_panda.yml
|
2020-10-15 17:30:34 -03:00 |
|
Jonhnathan
|
0926d76449
|
Update win_apt_equationgroup_dll_u_load.yml
|
2020-10-15 17:29:44 -03:00 |
|
Jonhnathan
|
8b593aa309
|
Update win_apt_empiremonkey.yml
|
2020-10-15 17:29:19 -03:00 |
|
Jonhnathan
|
00232982b2
|
Update win_apt_emissarypanda_sep19.yml
|
2020-10-15 17:28:33 -03:00 |
|
Jonhnathan
|
54f1a0c583
|
Update win_apt_elise.yml
|
2020-10-15 17:28:07 -03:00 |
|
Jonhnathan
|
d074ea110f
|
Update win_apt_dragonfly.yml
|
2020-10-15 17:27:42 -03:00 |
|
Jonhnathan
|
5eac9e5161
|
Update win_apt_cloudhopper.yml
|
2020-10-15 17:27:27 -03:00 |
|
Jonhnathan
|
2cdead8778
|
Update win_apt_chafer_mar18.yml
|
2020-10-15 17:26:58 -03:00 |
|
Jonhnathan
|
96ef4733c3
|
Update win_apt_bluemashroom.yml
|
2020-10-15 17:25:17 -03:00 |
|
Jonhnathan
|
ca31849be1
|
Update win_apt_bear_activity_gtr19.yml
|
2020-10-15 17:24:56 -03:00 |
|
Jonhnathan
|
10522becc3
|
Update win_apt_apt29_thinktanks.yml
|
2020-10-15 17:24:03 -03:00 |
|
Jonhnathan
|
bc1efd9843
|
Update sysmon_logon_scripts_userinitmprlogonscript_proc.yml
|
2020-10-15 17:23:44 -03:00 |
|
Jonhnathan
|
e0c538fdd4
|
Update sysmon_malware_verclsid_shellcode.yml
|
2020-10-15 17:19:06 -03:00 |
|
Jonhnathan
|
93faca413e
|
Update sysmon_lsass_memdump.yml
|
2020-10-15 17:17:57 -03:00 |
|
Jonhnathan
|
af5c88e5d5
|
Update sysmon_lazagne_cred_dump_lsass_access.yml
|
2020-10-15 17:17:39 -03:00 |
|
Jonhnathan
|
a554c3df23
|
Update sysmon_invoke_phantom.yml
|
2020-10-15 17:17:19 -03:00 |
|
Jonhnathan
|
1878aa5fbd
|
Update sysmon_cmstp_execution.yml
|
2020-10-15 17:16:50 -03:00 |
|
Jonhnathan
|
ce4e22750d
|
Update powershell_winlogon_helper_dll.yml
|
2020-10-15 17:15:23 -03:00 |
|
Jonhnathan
|
efe9c2d3d6
|
Update powershell_shellcode_b64.yml
|
2020-10-15 17:14:01 -03:00 |
|
Jonhnathan
|
013533fceb
|
Update powershell_prompt_credentials.yml
|
2020-10-15 17:13:16 -03:00 |
|
Jonhnathan
|
8cf2596068
|
Update powershell_malicious_keywords.yml
|
2020-10-15 17:12:08 -03:00 |
|
Jonhnathan
|
ec10d5a61f
|
Update powershell_malicious_commandlets.yml
|
2020-10-15 17:11:20 -03:00 |
|