SigmaHQ/rules/windows/builtin
2017-02-28 17:52:40 +01:00
..
win_alert_mimikatz_keywords.yml Rule review 2017-02-24 23:44:42 +01:00
win_av_relevant_match.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_add_sid_history.yml Added new rules 2017-02-19 22:43:27 +01:00
win_susp_dsrm_password_change.yml Added new rules 2017-02-19 22:43:27 +01:00
win_susp_eventlog_cleared.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_failed_logon_reasons.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_failed_logons_single_source.yml Removed 'last' keyword from 'timeframe' fields 2017-02-28 17:52:40 +01:00
win_susp_kerberos_manipulation.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_lsass_dump.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_rc4_kerberos.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00
win_susp_security_eventlog_cleared.yml Removed lists from log source section 2017-02-19 11:08:40 +01:00