mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
8d6a507ec4
* Checked all rules against Mordor and EVTX samples datasets * Added field names * Some severity adjustments * Fixes |
||
---|---|---|
.. | ||
powershell_alternate_powershell_hosts.yml | ||
powershell_clear_powershell_history.yml | ||
powershell_data_compressed.yml | ||
powershell_dnscat_execution.yml | ||
powershell_downgrade_attack.yml | ||
powershell_exe_calling_ps.yml | ||
powershell_invoke_obfuscation_obfuscated_iex.yml | ||
powershell_malicious_commandlets.yml | ||
powershell_malicious_keywords.yml | ||
powershell_ntfs_ads_access.yml | ||
powershell_prompt_credentials.yml | ||
powershell_psattack.yml | ||
powershell_remote_powershell_session.yml | ||
powershell_shellcode_b64.yml | ||
powershell_suspicious_download.yml | ||
powershell_suspicious_invocation_generic.yml | ||
powershell_suspicious_invocation_specific.yml | ||
powershell_suspicious_keywords.yml | ||
powershell_winlogon_helper_dll.yml |