Denys Iuzvyk
|
774be4d008
|
Escaped '\*' to '\*' where required
|
2019-09-04 14:05:58 +03:00 |
|
Thomas Patzke
|
25c0330dca
|
Added filter
|
2019-05-10 00:20:56 +02:00 |
|
Karneades
|
b47900fbee
|
Add default path to filter for explorer in exe anomaly rule
|
2019-04-21 17:42:47 +02:00 |
|
Thomas Patzke
|
49beb5d1a8
|
Integrated PR from @P4T12ICK in existing rule
PR #321
|
2019-04-21 00:28:40 +02:00 |
|
Karneades
|
d75ea35295
|
Restrict whitelist filter in system exe anomaly rule
|
2019-04-18 22:06:12 +02:00 |
|
Yugoslavskiy Daniil
|
8bec627ff1
|
fixed multiple tags issue
|
2019-03-06 06:09:37 +01:00 |
|
mrblacyk
|
99595a7f89
|
Added missing tags and some minor improvements
|
2019-03-05 23:25:49 +01:00 |
|
Thomas Patzke
|
7602309138
|
Increased indentation to 4
* Converted (to generic sigma) rules
* Converter outputs by default with indentation 4
|
2019-03-02 00:14:20 +01:00 |
|
Thomas Patzke
|
c922f7d73f
|
Merge branch 'master' into project-1
|
2019-02-26 00:24:46 +01:00 |
|
Thomas Patzke
|
96eb460944
|
Converted Sysmon/1 and Security/4688 to generic process creation rules
|
2019-01-16 23:36:31 +01:00 |
|