SigmaHQ/rules/windows
2020-10-28 11:38:39 +03:00
..
builtin Delete win_rdp_session_hijacking.yml 2020-10-28 11:38:39 +03:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
file_event Update win_susp_multiple_files_renamed_or_deleted.yml 2020-10-28 11:20:26 +03:00
image_load Update sysmon_tttracer_mod_load.yml 2020-10-09 09:34:05 +03:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection added missing ATT&CK v6.3 IDs with comments and removed unnecessary "modified" attributes 2020-08-25 23:51:22 +00:00
other Merge pull request #1007 from d4rk-d4nph3/master 2020-09-15 15:45:00 +02:00
powershell Merge pull request #1060 from svch0stz/oscd6 2020-10-13 22:59:25 +02:00
process_access fix typos, update tags 2020-09-13 15:46:45 +02:00
process_creation Merge pull request #1039 from Vasilisa-L/oscd 2020-10-14 00:24:41 +02:00
registry_event Merge pull request #1124 from bczyz1/oscd-sprint-2 2020-10-13 00:56:33 +02:00
sysmon Merge pull request #1065 from nsaddler/oscd1 2020-10-13 22:33:14 +02:00