SigmaHQ/rules/windows
frack113 77c6b74c72
Merge pull request #1985 from mvelazc0/master
Adding Petitpotam/ADCS attack vector detections
2021-09-03 19:06:03 +02:00
..
builtin Merge pull request #1985 from mvelazc0/master 2021-09-03 19:06:03 +02:00
create_remote_thread Cleanup PS rules 2021-08-21 09:58:58 +02:00
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load Update cve tags 2021-08-24 10:27:27 +02:00
file_delete Update cve tags 2021-08-24 10:27:27 +02:00
file_event chore: move level/falsepositives to bottom 2021-09-02 14:55:17 +02:00
image_load Update cve tags 2021-08-24 10:27:27 +02:00
malware Update tags 2021-09-01 10:33:57 +02:00
network_connection add missing tags 2021-09-01 12:54:21 +02:00
other detection for proxyshell MSF module 2021-08-31 12:51:16 +02:00
pipe_created Merge pull request #1973 from klingerko/cs_namedpipe_updates 2021-09-02 15:25:01 +02:00
powershell Merge pull request #1975 from frack113/red_T1564.004_2 2021-09-03 08:12:08 +02:00
process_access bulk of new rules to match working UACMe UAC bypasses 2021-08-31 12:51:21 +02:00
process_creation fixed date: switched day/month 2021-09-03 12:03:38 +02:00
raw_access_thread Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
registry_event fix: rename filter 2021-09-03 13:26:34 +02:00
sysmon Fix invalid tags 2021-08-25 09:15:57 +02:00
wmi_event fix: tags for WMI / execution / persistence 2021-09-01 16:34:50 +02:00