Florian Roth
|
3a378f08ea
|
Bugfix in Adwind rule - typo in typo
|
2017-11-10 12:51:54 +01:00 |
|
Florian Roth
|
6e4e857456
|
Improved Adwind Sigma rule
|
2017-11-10 12:39:08 +01:00 |
|
Florian Roth
|
57d56dddb7
|
Improved Adwind RAT rule
|
2017-11-09 18:53:46 +01:00 |
|
Florian Roth
|
b558f5914e
|
Added reference to Tom Ueltschie's slides
|
2017-11-09 18:30:50 +01:00 |
|
Florian Roth
|
781db7404e
|
Updated Adwind RAT rule
|
2017-11-09 18:28:27 +01:00 |
|
Florian Roth
|
970f01f9f2
|
Renamed file for consistency
|
2017-11-09 15:43:32 +01:00 |
|
Florian Roth
|
a042105aa1
|
Rule: Adwind RAT / JRAT javaw.exe process starts in AppData folder
|
2017-11-09 15:43:32 +01:00 |
|
Thomas Patzke
|
5035c9c490
|
Converted Windows 4688-only rules into 4688 and Sysmon/1 collections
|
2017-11-01 22:12:14 +01:00 |
|
Thomas Patzke
|
986c9ff9b7
|
Added field names to first rules
|
2017-09-12 23:54:04 +02:00 |
|
Florian Roth
|
950a00f33e
|
Updated Petya rule
|
2017-06-28 12:52:58 +02:00 |
|
Florian Roth
|
ece1d7e3a8
|
Added perfc.dat keyword to NotPetya rule
|
2017-06-28 10:35:42 +02:00 |
|
Florian Roth
|
a3e0e37163
|
NotPetya Title Fixed
|
2017-06-28 09:12:39 +02:00 |
|
Florian Roth
|
8c437de970
|
NotPetya Sigma Rule for Sysmon Events
|
2017-06-28 09:09:12 +02:00 |
|
Florian Roth
|
8f525d2f01
|
Wannacry Rules Reorg and Renaming
|
2017-06-28 09:08:53 +02:00 |
|