.. |
sysmon_abusing_azure_browser_sso.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_ads_executable.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_alternate_powershell_hosts_moduleload.yml
|
10 rules from THP - contributing soon
|
2020-10-12 15:42:34 -04:00 |
sysmon_alternate_powershell_hosts_pipe.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_apt_turla_namedpipes.yml
|
refactor: moved rues from 'apt' folder in respective folders
|
2020-02-01 17:59:26 +01:00 |
sysmon_cactustorch.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_cmstp_execution.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_cobaltstrike_process_injection.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_createremotethread_loadlibrary.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_cred_dump_tools_named_pipes.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_dcom_iertutil_dll_hijack.yml
|
10 rules from THP - contributing soon
|
2020-10-12 15:42:34 -04:00 |
sysmon_high_integrity_sdclt.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_mal_namedpipes.yml
|
Add Covenant default named pipe
|
2019-12-18 15:19:47 +00:00 |
sysmon_new_application_appcompat.yml
|
Updated - GitHub Action / Test Sigma
|
2020-10-12 21:34:07 -04:00 |
sysmon_password_dumper_lsass.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_possible_dns_rebinding.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_powershell_execution_pipe.yml
|
10 rules from THP - contributing soon
|
2020-10-12 15:42:34 -04:00 |
sysmon_raw_disk_access_using_illegitimate_tools.yml
|
Rule fixes
|
2020-02-20 23:00:16 +01:00 |
sysmon_removal_com_hijacking_registry_key.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_sdclt_child_process.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_startup_folder_file_write.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_susp_pfx_file_creation.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_susp_powershell_rundll32.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_susp_python_image_load.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_susp_system_drawing_load.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_susp_webdav_client_execution.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_suspicious_remote_thread.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_sysinternals_sdelete_file_deletion.yml
|
16 rules from DH APT29 day 1 - contributing soon
|
2020-10-12 18:13:13 -04:00 |
sysmon_sysinternals_sdelete_registry_keys.yml
|
Updated - GitHub Action / Test Sigma
|
2020-10-12 21:34:07 -04:00 |
sysmon_wdigest_registry_modification.yml
|
10 rules from THP - contributing soon
|
2020-10-12 15:42:34 -04:00 |
sysmon_wmi_event_subscription.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_wmi_susp_scripting.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_wmiprvse_wbemcomn_dll_hijack.yml
|
10 rules from THP - contributing soon
|
2020-10-12 15:42:34 -04:00 |