SigmaHQ/rules/apt
2019-03-04 16:51:39 +03:00
..
apt_apt29_thinktanks.yml updated to use process_creation 2019-03-02 21:05:15 +03:00
apt_apt29_tor.yml Fixing failed CI build - take 2 2019-03-04 16:51:39 +03:00
apt_babyshark.yml Increased indentation to 4 2019-03-02 00:14:20 +01:00
apt_bear_activity_gtr19.yml Increased indentation to 4 2019-03-02 00:14:20 +01:00
apt_carbonpaper_turla.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00
apt_chafer_mar18.yml Extended rule, modified timestamp 2019-03-01 13:36:54 +01:00
apt_cloudhopper.yml updated to use process_creation 2019-03-02 21:05:15 +03:00
apt_dragonfly.yml updated to use process_creation 2019-03-02 21:05:15 +03:00
apt_elise.yml updated to use process_creation 2019-03-02 21:05:15 +03:00
apt_equationgroup_c2.yml Fixed log source and field names 2018-08-04 22:58:19 +02:00
apt_equationgroup_dll_u_load.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_equationgroup_lnx.yml Removed duplicate filters 2019-01-25 12:21:57 +03:00
apt_hurricane_panda.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_judgement_panda_gtr19.yml Increased indentation to 4 2019-03-02 00:14:20 +01:00
apt_pandemic.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00
apt_slingshot.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_sofacy_zebrocy.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_sofacy.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_stonedrill.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00
apt_ta17_293a_ps.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00
apt_tropictrooper.yml Updated to use the new process_creation logsource 2019-03-04 16:13:27 +03:00
apt_turla_commands.yml Escaped '\*' to '\\*' where required 2019-02-03 00:24:57 +01:00
apt_turla_namedpipes.yml Replace "logsource: description" with "definition" to match the specs 2018-11-15 09:00:06 +03:00
apt_turla_service_png.yml Turla PNG Dropper Service Name 2018-11-23 08:46:20 +01:00
apt_unidentified_nov_18.yml Bugfix: wrong field for 4688 process creation events 2018-12-11 16:10:15 +01:00
apt_zxshell.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00
crime_fireball.yml Add tags to APT rules 2018-07-25 09:50:01 +02:00