SigmaHQ/rules/windows
Sam0x90 0e8a46aaf7
Update win_subp_svchost rule
Adding rpcnet.exe as ParentImage
2019-04-16 15:00:06 +02:00
..
builtin Update win_lm_namedpipe.yml 2019-04-04 18:22:50 +02:00
malware Update win_mal_ursnif.yml 2019-04-14 11:51:13 -05:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell Added missing tags and some minor improvements 2019-03-05 23:25:49 +01:00
process_creation Update win_subp_svchost rule 2019-04-16 15:00:06 +02:00
sysmon Rule: added date to Tom's WMI rule 2019-04-15 09:06:53 +02:00