SigmaHQ/rules/windows
Florian Roth 36bcd1c54e
Merge pull request #443 from EccoTheFlintstone/aduserbck
fix FP : field null value can be '-'
2019-09-25 17:43:22 +02:00
..
builtin Merge pull request #443 from EccoTheFlintstone/aduserbck 2019-09-25 17:43:22 +02:00
malware Rule: separate Ryuk rule created for VBurovs strings 2019-08-06 10:33:46 +02:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell powershell false positives 2019-09-06 03:54:19 -04:00
process_creation Merge pull request #451 from EccoTheFlintstone/sysmon_clean 2019-09-25 17:28:23 +02:00
sysmon sysmon rules cleanup and move to process_creation 2019-09-11 10:24:43 -04:00