Yugoslavskiy Daniil
|
42c4079ed8
|
att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other
|
2020-08-25 01:09:17 +02:00 |
|
Ivan Kirillov
|
0fbfcc6ba9
|
Initial round of subtechnique updates
|
2020-06-16 14:46:08 -06:00 |
|
j91321
|
3c74d8b87d
|
Add correct Source to detection to avoid FP
|
2020-03-24 19:49:24 +01:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Yugoslavskiy Daniil
|
05cc7e455d
|
atc review
|
2019-03-06 05:25:12 +01:00 |
|
David Spautz
|
e275d44462
|
Add tags to windows builtin rules
|
2018-07-24 07:50:32 +02:00 |
|
Thomas Patzke
|
b1bfa64231
|
Removed redundant 'EventLog' conditions
|
2018-03-26 00:36:40 +02:00 |
|
SherifEldeeb
|
112a0939d7
|
Change "reference" to "references" to match new schema
|
2018-01-28 02:12:19 +03:00 |
|
Florian Roth
|
aca70e57ec
|
Massive Title Cleanup
|
2018-01-27 10:57:30 +01:00 |
|
Thomas Patzke
|
f768bf3d61
|
Fixed parse errors
|
2017-08-02 22:49:15 +02:00 |
|
Florian Roth
|
ae4cab6783
|
Corrected - no lists needed
|
2017-05-25 12:07:11 +02:00 |
|
dimi
|
0b8c82b75b
|
1) Add Windows DHCP Server Callout DLL rules: Sysmon, failed loading and successfull loading
2) correct typo in dns server rule
|
2017-05-15 20:58:31 +02:00 |
|