SigmaHQ/rules/windows
Florian Roth 2055da991f
Merge pull request #1691 from SigmaHQ/rule-devel
Rules: scripts from Temp folders, reg disable sec services
2021-07-15 08:35:54 +02:00
..
builtin Merge branch 'config-adjustments' into rule-devel 2021-07-14 08:35:47 +02:00
create_remote_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load Merging upstream updates 2021-07-01 12:18:30 +05:45
file_delete Added rule for deletion of DLLs by PrintNightmare 2021-07-01 16:33:55 +05:45
file_event Update sysmon_susp_pfx_file_creation.yml 2021-07-04 10:38:53 +08:00
image_load Merge branch 'config-adjustments' into rule-devel 2021-07-14 08:35:47 +02:00
malware fix some typo error 2021-07-12 09:40:18 +02:00
network_connection Merge branch 'master' into master 2021-07-11 00:32:55 +02:00
other medium level rule for Windows Defender Exclusions 2021-07-13 13:16:25 +02:00
pipe_created Merging upstream updates 2021-07-01 12:18:30 +05:45
powershell Insert modified date 2021-07-06 20:56:31 +08:00
process_access fix 3 times the same name file 2021-07-02 11:01:07 +02:00
process_creation Merge pull request #1691 from SigmaHQ/rule-devel 2021-07-15 08:35:54 +02:00
raw_access_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
registry_event Merge pull request #1676 from d4rk-d4nph3/master 2021-07-12 14:02:49 +02:00
sysmon Merge pull request #1674 from frack113/fix_small_errors 2021-07-12 15:23:55 +02:00
wmi_event Merging upstream updates 2021-07-01 12:18:30 +05:45