yugoslavskiy
|
cc7aebe9b6
|
Update win_service_execution.yml
|
2019-11-05 04:42:53 +03:00 |
|
yugoslavskiy
|
ac95d840b4
|
Update powershell_winlogon_helper_dll.yml
|
2019-11-05 04:33:07 +03:00 |
|
yugoslavskiy
|
479aafe466
|
Update win_service_execution.yml
|
2019-11-05 04:26:19 +03:00 |
|
yugoslavskiy
|
37674b944f
|
Update win_query_registry.yml
|
2019-11-05 03:04:46 +03:00 |
|
yugoslavskiy
|
9d9de64387
|
Update win_query_registry.yml
|
2019-11-05 03:00:33 +03:00 |
|
yugoslavskiy
|
27e63abcc4
|
Update and rename win_custom_service_execution.yml to win_service_execution.yml
|
2019-11-05 02:57:15 +03:00 |
|
yugoslavskiy
|
3d5f5e2fe7
|
Update win_custom_service_execution.yml
|
2019-11-05 02:56:50 +03:00 |
|
yugoslavskiy
|
66bfbd0af9
|
Update and rename win_service_execution.yml to win_custom_service_execution.yml
|
2019-11-05 02:55:41 +03:00 |
|
yugoslavskiy
|
c147863eb3
|
Update powershell_data_compressed.yml
|
2019-11-05 02:38:36 +03:00 |
|
yugoslavskiy
|
b755d4fb68
|
Update and rename win_system_owner_user_discovery.yml to win_local_system_owner_account_discovery.yml
|
2019-11-05 02:31:20 +03:00 |
|
yugoslavskiy
|
9831897b6b
|
Update win_xsl_script_processing.yml
|
2019-11-05 01:32:29 +03:00 |
|
yugoslavskiy
|
ce55f80fb6
|
Update win_xsl_script_processing.yml
|
2019-11-05 01:31:55 +03:00 |
|
zinint
|
cd1cd48619
|
Delete win_app_windows_discovery.yml
|
2019-11-05 01:18:26 +03:00 |
|
zinint
|
a3ec56da07
|
Update win_xsl_script_processing.yml
|
2019-11-05 00:02:19 +03:00 |
|
zinint
|
fd6875485b
|
Add files via upload
|
2019-11-05 00:00:14 +03:00 |
|
zinint
|
cd43354c04
|
Delete sysmon_xsl_script_processing.yml
|
2019-11-04 23:47:23 +03:00 |
|
zinint
|
2679baddcd
|
Delete powershell_network_sniffing.yml
|
2019-11-04 23:46:43 +03:00 |
|
yugoslavskiy
|
e81f4f0ea6
|
Update sysmon_xsl_script_processing.yml
|
2019-11-04 23:42:47 +03:00 |
|
yugoslavskiy
|
b565398bc5
|
Update win_network_sniffing.yml
|
2019-11-04 23:02:03 +03:00 |
|
yugoslavskiy
|
e38116fce2
|
Update and rename win_data_compressed.yml to win_data_compressed_with_rar.yml
|
2019-11-04 22:55:32 +03:00 |
|
yugoslavskiy
|
f880fa82b5
|
Rename process_creation_change_default_file_association.yml to win_change_default_file_association.yml
|
2019-11-04 22:48:13 +03:00 |
|
yugoslavskiy
|
cbf01aa51e
|
Update and rename win_change_default_file_association.yml to process_creation_change_default_file_association.yml
|
2019-11-04 22:46:55 +03:00 |
|
zinint
|
60bf34e220
|
T1042
|
2019-10-30 23:30:56 +03:00 |
|
zinint
|
12ef86fcbe
|
t1040
|
2019-10-30 23:18:37 +03:00 |
|
zinint
|
b3b203e5b1
|
t1040
|
2019-10-30 23:15:19 +03:00 |
|
zinint
|
c243c4e210
|
T1035
|
2019-10-29 20:58:52 +03:00 |
|
zinint
|
87c8326133
|
T1033
|
2019-10-27 23:49:07 +03:00 |
|
zinint
|
55eaae1cea
|
Rename win_app_windows_descovery.yml to win_app_windows_discovery.yml
|
2019-10-27 23:15:10 +03:00 |
|
zinint
|
93b867024c
|
T1012
|
2019-10-27 23:13:03 +03:00 |
|
zinint
|
6e94e798be
|
t1010
|
2019-10-25 16:12:51 +03:00 |
|
zinint
|
aef5fa3c2b
|
Rename powershell_winlogon_helper_dll.yaml to powershell_winlogon_helper_dll.yml
|
2019-10-24 16:37:38 +03:00 |
|
zinint
|
5a98fdbbbd
|
ART t1004
|
2019-10-24 16:33:29 +03:00 |
|
zinint
|
317e9d3df9
|
PS Data Compressed attack.t1002
PS Data Compressed attack.t1002
|
2019-10-24 15:43:46 +03:00 |
|
zinint
|
7c5dc0ca01
|
Update win_data_compressed.yml
|
2019-10-24 15:34:13 +03:00 |
|
zinint
|
49f9b797a7
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 15:20:15 +03:00 |
|
zinint
|
a8bd2c8e78
|
Update win_data_compressed.yml
|
2019-10-22 14:57:53 +03:00 |
|
zinint
|
74d1fef8b8
|
Update win_data_compressed.yml
|
2019-10-22 14:53:43 +03:00 |
|
zinint
|
cc6d4b05ac
|
OSCD Task 7 : ART T1002 Exfiltration With Rar
OSCD Task 7 : ART T1002 Compress Data for Exfiltration With Rar
|
2019-10-22 14:00:52 +03:00 |
|
zinint
|
daf1034621
|
Update win_possible_applocker_bypass.yml
|
2019-10-22 00:54:29 +03:00 |
|
zinint
|
789782ef59
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:08:46 +03:00 |
|
zinint
|
56f807cb44
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:06:54 +03:00 |
|
zinint
|
0d8eff0d86
|
Update sysmon_xsl_script_processing.yml
|
2019-10-22 00:06:10 +03:00 |
|
zinint
|
a1d72f20c8
|
Update sysmon_xsl_script_processing.yml
|
2019-10-21 23:51:39 +03:00 |
|
zinint
|
5248f83fb3
|
Update sysmon_xsl_script_processing.yml
|
2019-10-21 23:46:11 +03:00 |
|
zinint
|
a685c9c3be
|
Update sysmon_xsl_script_processing.yml
|
2019-10-21 23:39:33 +03:00 |
|
zinint
|
784d7138ca
|
OSCD Task 7 ART T1220
OSCD Task 7 ART T1220 rule add
|
2019-10-21 22:22:55 +03:00 |
|
Florian Roth
|
deb3ecf404
|
fix: relevant fields in lsass dll load rule
|
2019-10-16 19:09:20 +02:00 |
|
Florian Roth
|
ab292a4029
|
rule: simplified Emotet rule
|
2019-10-16 15:29:42 +02:00 |
|
Florian Roth
|
c396526f40
|
rule: LSASS DLL load via undocumented Registry key
https://twitter.com/SBousseaden/status/1183745981189427200
|
2019-10-16 13:18:44 +02:00 |
|
Florian Roth
|
5d143f4f22
|
rule: emotet rule references extended
|
2019-10-16 13:18:44 +02:00 |
|