SigmaHQ/rules/windows/sysmon
yugoslavskiy e1fd69f548
Merge pull request #1179 from SanWieb/OSCD_regedit_3
[OSCD] regedit.exe LOLbas 72 [3]
2021-01-06 00:16:45 +03:00
..
silenttrinity_stager_msbuild_activity.yml Update silenttrinity_stager_msbuild_activity.yml 2020-10-26 17:00:50 +05:30
sysmon_abusing_azure_browser_sso.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_accessing_winapi_in_powershell_credentials_dumping.yml Update sysmon_accessing_winapi_in_powershell_credentials_dumping.yml 2020-10-13 22:32:55 +02:00
sysmon_ads_executable.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_alternate_powershell_hosts_pipe.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_apt_turla_namedpipes.yml refactor: moved rues from 'apt' folder in respective folders 2020-02-01 17:59:26 +01:00
sysmon_cactustorch.yml Remove additional backlash 2020-11-20 02:04:28 -03:00
sysmon_cmstp_execution.yml Update sysmon_cmstp_execution.yml 2020-10-15 20:13:39 -03:00
sysmon_cobaltstrike_process_injection.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_createremotethread_loadlibrary.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_cred_dump_tools_named_pipes.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_mal_namedpipes.yml Add Covenant default named pipe 2019-12-18 15:19:47 +00:00
sysmon_password_dumper_lsass.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_possible_dns_rebinding.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_psexec_pipes_artifacts.yml Update sysmon_psexec_pipes_artifacts.yml 2020-10-07 14:43:25 +03:00
sysmon_raw_disk_access_using_illegitimate_tools.yml Rule fixes 2020-02-20 23:00:16 +01:00
sysmon_regedit_export_to_ads.yml Fixed field typo 2020-10-15 15:27:11 +02:00
sysmon_susp_powershell_rundll32.yml Update sysmon_susp_powershell_rundll32.yml 2020-10-15 20:14:23 -03:00
sysmon_suspicious_remote_thread.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_wmi_event_subscription.yml review windows/sysmon 2020-08-29 02:03:28 +02:00
sysmon_wmi_susp_scripting.yml Update detection Logic 2020-11-20 02:10:27 -03:00