SigmaHQ/rules/windows
frack113 a04fbe2a99
Merge pull request #1901 from frack113/redcanary
Redcanary Powershell Suspicious Win32_PnPEntity T1120
2021-08-23 19:44:16 +02:00
..
builtin Replace by default windows fieldnames 2021-08-23 15:24:48 +02:00
create_remote_thread Cleanup PS rules 2021-08-21 09:58:58 +02:00
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load fix: more changes to incomplete windivert rule 2021-08-07 11:22:44 +02:00
file_delete Added rule for deletion of DLLs by PrintNightmare 2021-07-01 16:33:55 +05:45
file_event Merge pull request #1892 from frack113/clean_PS 2021-08-21 18:04:52 +02:00
image_load update modified after FP fix 2021-08-18 18:17:53 +02:00
malware Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
network_connection Merge branch 'master' into master 2021-07-11 00:32:55 +02:00
other feat: Add rule for malicious CSR export on Exchange 2021-08-23 11:20:30 +02:00
pipe_created fix: re CS rule 2021-07-30 08:24:41 +02:00
powershell add powershell_suspicious_win32_pnpentity 2021-08-23 13:17:35 +02:00
process_access Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
process_creation update references 2021-08-23 13:30:46 +02:00
raw_access_thread Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
registry_event Replace old mitre techniques by new one 2021-08-22 13:57:56 +02:00
sysmon fix: Correct incorrect message / keyword usage 2021-08-12 16:28:07 +02:00
wmi_event Merging upstream updates 2021-07-01 12:18:30 +05:45