SigmaHQ/rules/windows/wmi_event
2021-09-01 16:34:50 +02:00
..
sysmon_wmi_event_subscription.yml - Remove 'service: sysmon' since defining the categories made the rules generic 2020-10-02 09:37:52 +02:00
sysmon_wmi_susp_encoded_scripts.yml fix: tags for WMI / execution / persistence 2021-09-01 16:34:50 +02:00
sysmon_wmi_susp_scripting.yml rule: extended WMI suspicious scripts rule 2021-09-01 13:57:48 +02:00