SigmaHQ/rules/windows
2019-02-06 19:21:16 +01:00
..
builtin Rule: Suspicious GUP.exe usage 2019-02-06 19:21:16 +01:00
malware Escaped '\*' to '\\*' where required 2019-02-03 00:24:57 +01:00
other Rule: WMI Persistence - FPs 2019-02-05 14:35:23 +01:00
powershell rule: false positive reduction in PowerShell rules 2019-01-22 16:37:36 +01:00
sysmon Added '/' prefix, -encode switch, better renamed certutil coverage 2019-02-06 10:45:32 -05:00