SigmaHQ/rules/windows
Florian Roth 04f7766d7a
Merge pull request #1319 from hieuttmmo/master
Detect Emotet DLL loading by looking rundll32.exe
2021-01-09 10:29:24 +01:00
..
builtin more AV event and suspicious commands 2021-01-07 17:54:19 +01:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
file_event Merge pull request #989 from oscd-initiative/master 2020-09-08 13:27:58 +02:00
image_load Merge pull request #989 from oscd-initiative/master 2020-09-08 13:27:58 +02:00
malware more AV event and suspicious commands 2021-01-07 17:54:19 +01:00
network_connection added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
other fix reference field + add test for references in plural form 2020-11-27 10:17:45 +01:00
powershell fix: Malicious Nishang PowerShell Commandlets FP with MDATP 2020-12-05 09:33:42 +01:00
process_access fix typos, update tags 2020-09-13 15:46:45 +02:00
process_creation Merge pull request #1319 from hieuttmmo/master 2021-01-09 10:29:24 +01:00
registry_event Merge pull request #1264 from omkar72/sdev-1 2020-12-21 18:28:59 +01:00
sysmon fix reference field + add test for references in plural form 2020-11-27 10:17:45 +01:00