SigmaHQ/rules/windows/sysmon
Thomas Patzke 15c6f9411b Rule review
* Typos
* Added false positive descriptions
2017-02-24 23:44:42 +01:00
..
sysmon_mimikatz_detection_lsass.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_mimikatz_inmemory_detection.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_password_dumper_lsass.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_susp_driver_load.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_susp_mmc_source.yml Rule review 2017-02-24 23:44:42 +01:00
sysmon_vul_java_remote_debugging.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_webshell_detection.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
sysmon_webshell_spawn.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00