SigmaHQ/rules/windows/create_remote_thread
2021-06-27 14:51:29 +02:00
..
sysmon_cactustorch.yml Merge branch 'master' of https://github.com/SigmaHQ/sigma 2021-04-15 01:25:48 +02:00
sysmon_cobaltstrike_process_injection.yml - Remove 'service: sysmon' since defining the categories made the rules generic 2020-10-02 09:37:52 +02:00
sysmon_createremotethread_loadlibrary.yml Update Threat Hunter Playbook Reference 2021-05-22 01:00:39 -03:00
sysmon_password_dumper_lsass.yml convert to TargetImage|endswith 2021-06-21 20:51:26 +02:00
sysmon_susp_powershell_rundll32.yml Merge branch 'master' of https://github.com/SigmaHQ/sigma 2021-04-15 01:25:48 +02:00
sysmon_suspicious_remote_thread.yml Updated rules with modifiers instead of '*' and remove trailing '\\' 2021-06-27 14:51:29 +02:00