SigmaHQ/rules/windows
2021-09-22 22:24:24 -05:00
..
builtin fix 4697 fieldname 2021-09-20 22:53:59 +02:00
create_remote_thread fix condition operator case 2021-09-10 13:51:52 +02:00
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Clean SyncAppvPublishingServer rules 2021-09-12 07:46:35 +02:00
dns_query split global sysmon_regsvr32_network_activity.yml 2021-09-21 10:33:47 +02:00
driver_load normalise name 2021-09-11 13:34:19 +02:00
file_delete Update cve tags 2021-08-24 10:27:27 +02:00
file_event fix: remove rule, too many FPs and no better matching criteria 2021-09-21 16:52:17 +02:00
image_load split global sysmon_tttracer_mod_load.yml 2021-09-21 10:39:02 +02:00
malware fix related 2021-09-11 14:22:01 +02:00
network_connection fix tests.py error 2021-09-21 10:52:37 +02:00
other split global win_defender_disabled.yml 2021-09-21 10:24:52 +02:00
pipe_created split global win_tool_psexec.yml 2021-09-21 10:10:48 +02:00
powershell add definition 2021-09-22 08:40:08 +02:00
process_access Various fixes 2021-09-07 23:38:07 +02:00
process_creation Update sysmon_atlassian_confluence_cve_2021_26084_exploit.yml 2021-09-22 22:24:24 -05:00
raw_access_thread Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
registry_event split global win_defender_disabled.yml 2021-09-21 10:24:52 +02:00
sysmon Merge pull request #2012 from frack113/upgrade_test 2021-09-11 15:29:19 +02:00
wmi_event fix: tags for WMI / execution / persistence 2021-09-01 16:34:50 +02:00