This website requires JavaScript.
Explore
Help
Register
Sign In
valitydev
/
SigmaHQ
Watch
14
Star
0
Fork
0
You've already forked SigmaHQ
mirror of
https://github.com/valitydev/SigmaHQ.git
synced
2024-11-08 02:08:54 +00:00
Code
Issues
Actions
Packages
Projects
Releases
Wiki
Activity
3934f6c756
SigmaHQ
/
rules
/
windows
History
yugoslavskiy
3934f6c756
add win_ad_object_writedac_access.yml, sysmon_createremotethread_loadlibrary.yml, sysmon_rdp_registry_modification.yml; modified win_account_backdoor_dcsync_rights.yml
2019-10-24 14:34:16 +02:00
..
builtin
add win_ad_object_writedac_access.yml, sysmon_createremotethread_loadlibrary.yml, sysmon_rdp_registry_modification.yml; modified win_account_backdoor_dcsync_rights.yml
2019-10-24 14:34:16 +02:00
malware
rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet
2019-10-04 16:17:34 +02:00
other
Converted to use the new process_creation data source
2019-03-09 20:57:59 +03:00
powershell
powershell false positives
2019-09-06 03:54:19 -04:00
process_creation
rule: another reference link for 'execution by ordinal'
2019-10-22 15:18:19 +02:00
sysmon
add win_ad_object_writedac_access.yml, sysmon_createremotethread_loadlibrary.yml, sysmon_rdp_registry_modification.yml; modified win_account_backdoor_dcsync_rights.yml
2019-10-24 14:34:16 +02:00