SigmaHQ/rules/windows
2021-09-07 09:21:44 +02:00
..
builtin Merge pull request #1979 from frack113/test_global 2021-09-06 08:44:14 +02:00
create_remote_thread Cleanup PS rules 2021-08-21 09:58:58 +02:00
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load Update cve tags 2021-08-24 10:27:27 +02:00
file_delete Update cve tags 2021-08-24 10:27:27 +02:00
file_event Merge pull request #1979 from frack113/test_global 2021-09-06 08:44:14 +02:00
image_load Update global id 2021-09-03 06:35:35 +02:00
malware Update global ID 2021-09-02 21:16:55 +02:00
network_connection update global id 2021-09-02 21:03:25 +02:00
other Merge pull request #1979 from frack113/test_global 2021-09-06 08:44:14 +02:00
pipe_created Update sysmon_mal_cobaltstrike_re.yml 2021-09-04 17:33:05 -05:00
powershell removed unneeded upper ticks 2021-09-07 09:21:44 +02:00
process_access bulk of new rules to match working UACMe UAC bypasses 2021-08-31 12:51:21 +02:00
process_creation fix: more upper case chars 2021-09-07 09:19:23 +02:00
raw_access_thread Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
registry_event Merge pull request #1979 from frack113/test_global 2021-09-06 08:44:14 +02:00
sysmon Update global ID 2021-09-02 21:16:55 +02:00
wmi_event fix: tags for WMI / execution / persistence 2021-09-01 16:34:50 +02:00