Yugoslavskiy Daniil
|
42c4079ed8
|
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
|
2020-08-25 01:09:17 +02:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
Tatsuya Ito
|
c815773b1a
|
enhancement rule
|
2020-05-19 18:05:51 +09:00 |
|
Florian Roth
|
e79e99c4aa
|
fix: fixed missing date fields in remaining files
|
2020-01-30 16:07:37 +01:00 |
|
Thomas Patzke
|
c47af5169c
|
Increased SID history rule severity
|
2019-12-03 14:28:46 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Florian Roth
|
9835950f04
|
rule: SID to AD object rule level adjusted
|
2019-11-09 12:49:54 +01:00 |
|
yugoslavskiy
|
803f2d4074
|
changed logic to detect events related to sid history adding
|
2019-07-17 04:28:21 +03:00 |
|
yugoslavskiy
|
310e3b7a44
|
rules/windows/builtin/win_susp_add_sid_history.yml improved
|
2019-07-17 03:55:02 +03:00 |
|
David Spautz
|
e275d44462
|
Add tags to windows builtin rules
|
2018-07-24 07:50:32 +02:00 |
|
SherifEldeeb
|
48441962cc
|
Change All "str" references to be "list"to mach schema update
|
2018-01-28 02:24:16 +03:00 |
|
SherifEldeeb
|
112a0939d7
|
Change "reference" to "references" to match new schema
|
2018-01-28 02:12:19 +03:00 |
|
Florian Roth
|
aad892c834
|
Windows Built-In rules > LogSource definition
|
2017-03-05 23:55:52 +01:00 |
|
Thomas Patzke
|
a4611d6dc6
|
Added new rules
From adsecurity.org:
* https://adsecurity.org/?p=1772
* https://adsecurity.org/?p=1714
|
2017-02-19 22:43:27 +01:00 |
|