SigmaHQ/rules/windows
Thomas Patzke 8ae824f09f Improved rules
Reduced false positives
2019-11-08 23:56:14 +01:00
..
builtin fix: bound windows event log rules to message field 2019-11-02 11:25:29 +01:00
malware rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet 2019-10-04 16:17:34 +02:00
other fix: bound keywords to field in WMI persistence rule 2019-10-29 19:22:41 +01:00
powershell Merge pull request #477 from zinint/oscd 2019-11-05 04:55:29 +03:00
process_creation Improved rules 2019-11-08 23:56:14 +01:00
sysmon Merge pull request #479 from alexpetrov12/master 2019-11-08 02:16:22 +03:00