SigmaHQ/rules/windows
2019-06-03 15:51:54 +02:00
..
builtin Rule: Scanner PoC for CVE-2019-0708 RDP RCE vuln 2019-06-02 09:52:18 +02:00
malware Update win_mal_ursnif.yml 2019-04-14 11:51:13 -05:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell Added missing tags and some minor improvements 2019-03-05 23:25:49 +01:00
process_creation event id deleted 2019-06-03 15:51:54 +02:00
sysmon changed to process_creation category 2019-06-03 15:47:24 +02:00