aw350m3
eb6b9be5a2
added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes
2020-08-25 23:51:22 +00:00
aw350m3
399f378269
att&ck tags review: windows/powershell, windows/process_access, windows/network_connection
2020-08-24 23:31:26 +00:00
aw350m3
08170bbcca
fix tags for suspicious outbound kerberos activity rule
2020-08-23 21:10:29 +00:00
aw350m3
4cdd8be354
Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:20:58 +00:00
aw350m3
80deaf84ca
windows/network_connection folder reviewed
2020-08-22 23:36:30 +00:00
Aidan Bracher
dcf20e580d
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
Florian Roth
d0c09f10a9
changed newline character to LF
2020-07-15 16:46:44 +02:00
Bart
308420bf7f
Update sysmon_dllhost_net_connections.yml
...
Fix @
2020-07-13 21:20:55 +02:00
Bart
007f62ba01
Add Dllhost WAN access
2020-07-13 21:12:37 +02:00
Thomas Patzke
939156fa6d
Introduced dns_query log source category
2020-07-05 23:29:51 +02:00
Brad Kish
8b3b312c4e
Proposed fix for https://github.com/Neo23x0/sigma/issues/889
...
This change removes dns events from the network connection category. The
one change is that sysmon_regsvr32_network_activity.yml needs to test
the network connection category separately from the DNS event id.
2020-07-03 16:28:19 -04:00
Florian Roth
9c0f9f398f
refactor: sysmon rule cleanup > generlization
2020-07-01 10:58:39 +02:00
Florian Roth
f3fedef8f5
Changed category names and remove sysmon log source
2020-06-24 17:41:21 +02:00
Steven Goossens
e5f36dd146
Added rules files split into folders
2020-06-10 16:32:30 +02:00