mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
9bfdcba400
add another detection rule for delegation via the attack described in harmj0y's blog: https://www.harmj0y.net/blog/redteaming/another-word-on-delegation/ |
||
---|---|---|
.. | ||
builtin | ||
malware | ||
other | ||
powershell | ||
sysmon |