SherifEldeeb
|
348728bdd9
|
Cleaning up empty list items
|
2018-01-28 02:36:39 +03:00 |
|
SherifEldeeb
|
48441962cc
|
Change All "str" references to be "list"to mach schema update
|
2018-01-28 02:24:16 +03:00 |
|
SherifEldeeb
|
112a0939d7
|
Change "reference" to "references" to match new schema
|
2018-01-28 02:12:19 +03:00 |
|
Thomas Patzke
|
986c9ff9b7
|
Added field names to first rules
|
2017-09-12 23:54:04 +02:00 |
|
Thomas Patzke
|
84418d2045
|
Merged builtin/win_susp_certutil_activity.yml with Sysmon rule
|
2017-08-02 00:04:28 +02:00 |
|
Florian Roth
|
cdf0894e6a
|
Corrected error in certutil rules (-f means force overwrite, not file)
> the -urlcache is the relevant command
|
2017-07-20 12:54:55 -06:00 |
|
Florian Roth
|
3a55b31da2
|
certutil file download - more generic approach
|
2017-07-20 12:48:47 -06:00 |
|
Florian Roth
|
b85d96e458
|
certutil detections (renamed, extended)
see https://twitter.com/subTee/status/888102593838362624
|
2017-07-20 12:38:10 -06:00 |
|