SigmaHQ/rules/windows
2021-07-11 09:29:43 +02:00
..
builtin Merge pull request #1637 from frack113/fix_win_rdp_reverse_tunnel.yml 2021-07-07 10:12:16 +02:00
create_remote_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load Merging upstream updates 2021-07-01 12:18:30 +05:45
file_delete Added rule for deletion of DLLs by PrintNightmare 2021-07-01 16:33:55 +05:45
file_event Update sysmon_susp_pfx_file_creation.yml 2021-07-04 10:38:53 +08:00
image_load Adjusted Spool Service DLL load rule 2021-07-11 09:29:43 +02:00
malware Fixed Spell Error 2021-07-02 11:47:20 -05:00
network_connection Update sysmon_remote_powershell_session_network.yml 2021-07-03 14:25:55 +08:00
other Added and updated Defender's tamper related rules 2021-07-05 20:30:07 +05:45
pipe_created Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell Insert modified date 2021-07-06 20:56:31 +08:00
process_access fix 3 times the same name file 2021-07-02 11:01:07 +02:00
process_creation Merge pull request #1649 from leegengyu/patch-9 2021-07-07 18:10:27 +02:00
raw_access_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
registry_event rule: PrinterNightmare Mimikatz update 2021-07-05 15:29:52 +02:00
sysmon Merging upstream updates 2021-07-01 12:18:30 +05:45
wmi_event Merging upstream updates 2021-07-01 12:18:30 +05:45