SigmaHQ/rules/windows
Brad Kish 7e06fd80fd Proposed fix for sysmon_uac_bypass_eventvwr
Issue: https://github.com/Neo23x0/sigma/issues/888

The rules were not merged correctly with the transition to sysmon categories.

Split the rule into separate documents: one for the registry_event and one for
the process_creation
2020-07-06 09:20:34 -04:00
..
builtin Merge branch 'master' of https://github.com/4A616D6573/sigma into pr-785 2020-07-02 23:04:59 +02:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
file_event Fixes for rules in the sysmon file_event category 2020-07-03 16:22:29 -04:00
image_load refactor: sysmon rule cleanup > generlization 2020-07-01 10:58:39 +02:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection Introduced dns_query log source category 2020-07-05 23:29:51 +02:00
other FIX: lint error for title 2020-06-28 11:05:19 +02:00
powershell Added new rule for pwsh_xor_cmd 2020-06-29 22:09:58 +02:00
process_access fix: broken links 2020-07-03 11:22:06 +02:00
process_creation rule: suspicious curl usage 2020-07-03 18:55:44 +02:00
registry_event Proposed fix for sysmon_uac_bypass_eventvwr 2020-07-06 09:20:34 -04:00
sysmon fix: broken links 2020-07-03 11:22:06 +02:00