SigmaHQ/rules/windows
2018-02-22 13:29:19 +01:00
..
builtin Detects successful logon with logon type 9 (NewCredentials) which matches the Overpass the Hash behavior of e.g Mimikatz's sekurlsa::pth module 2018-02-12 21:57:22 +01:00
malware Cleaning up empty list items 2018-01-28 02:36:39 +03:00
other Change All "str" references to be "list"to mach schema update 2018-01-28 02:24:16 +03:00
powershell Cleaning up empty list items 2018-01-28 02:36:39 +03:00
sysmon Fixed file names "vuln" > "exploit" 2018-02-22 13:29:19 +01:00