SigmaHQ/rules/windows
Florian Roth 60795f7050
Update win_susp_adfind.yml
Fear that a simple adfind.exe causes too many false positives
2020-09-26 17:02:39 +02:00
..
builtin win_susp_failed_logon_source rule 2020-05-06 22:24:02 +02:00
deprecated Merge branch 'master' into oscd 2020-02-03 23:13:16 +01:00
malware Changed level to ciritcal 2020-05-11 10:40:23 +02:00
other fix: converted CRLF line break to LF 2020-03-25 14:36:34 +01:00
powershell fix incorrect use of action global 2020-05-06 22:53:02 +02:00
process_creation Update win_susp_adfind.yml 2020-09-26 17:02:39 +02:00
sysmon Update condition to filter out printer port 2020-05-14 18:22:49 +07:00