SigmaHQ/rules/windows
2019-02-06 10:59:09 +01:00
..
builtin added reverted base64 with dosfuscation 2019-02-06 10:59:09 +01:00
malware Escaped '\*' to '\\*' where required 2019-02-03 00:24:57 +01:00
other Rule: WMI Persistence - FPs 2019-02-05 14:35:23 +01:00
powershell rule: false positive reduction in PowerShell rules 2019-01-22 16:37:36 +01:00
sysmon Detects Executables without FileVersion,Description,Product,Company likely created with py2exe 2019-02-06 10:58:37 +01:00