SigmaHQ/rules/windows
2019-09-06 06:21:42 -04:00
..
builtin rule: user added to local administrator: handle non english systems by using group sid instead of name 2019-09-06 06:21:42 -04:00
malware Rule: separate Ryuk rule created for VBurovs strings 2019-08-06 10:33:46 +02:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell powershell false positives 2019-09-06 03:54:19 -04:00
process_creation rule: image debugger 2019-09-06 10:28:20 +02:00
sysmon fix: duplicate rule 2019-09-06 10:30:47 +02:00