SigmaHQ/rules/windows
Florian Roth af4d546408
Merge pull request #1282 from Neo23x0/rule-devel
fix: FPs with notepad++ GUP rule
2020-11-10 13:39:28 +01:00
..
builtin Added win_vul_cve_2020_1472 rule 2020-09-15 15:13:53 +02:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
file_event Merge pull request #989 from oscd-initiative/master 2020-09-08 13:27:58 +02:00
image_load Merge pull request #989 from oscd-initiative/master 2020-09-08 13:27:58 +02:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
other Merge pull request #1007 from d4rk-d4nph3/master 2020-09-15 15:45:00 +02:00
powershell fix: FP with expression 2020-10-20 13:11:10 +02:00
process_access fix typos, update tags 2020-09-13 15:46:45 +02:00
process_creation Merge pull request #1282 from Neo23x0/rule-devel 2020-11-10 13:39:28 +01:00
registry_event added event type & changed technique 2020-10-02 09:22:14 +05:30
sysmon Revert "att&ck tags review: windows/process_creation part 5" 2020-09-07 01:28:08 +04:00