SigmaHQ/rules/windows
frack113 1b480f2ee6
Merge pull request #1819 from frack113/split_1802_builtin
Correct lists with only 1 value
2021-08-13 12:43:26 +02:00
..
builtin remove change for Message rule 2021-08-13 11:01:33 +02:00
create_remote_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Merging upstream updates 2021-07-01 12:18:30 +05:45
dns_query Removed EventID from generic DNS query rule 2021-07-08 07:41:11 +02:00
driver_load fix: more changes to incomplete windivert rule 2021-08-07 11:22:44 +02:00
file_delete Added rule for deletion of DLLs by PrintNightmare 2021-07-01 16:33:55 +05:45
file_event fix TargetFilename case error 2021-08-06 08:43:05 +02:00
image_load Merge branch 'config-adjustments' into rule-devel 2021-07-14 08:35:47 +02:00
malware Update win_mal_flowcloud.yml 2021-07-22 11:09:45 +02:00
network_connection Merge branch 'master' into master 2021-07-11 00:32:55 +02:00
other Merge pull request #1784 from frack113/winlogbeat-modules-enabled 2021-08-12 19:14:17 +02:00
pipe_created fix: re CS rule 2021-07-30 08:24:41 +02:00
powershell Merge pull request #1762 from frack113/redcanary_collection 2021-08-05 15:49:10 +02:00
process_access new rule LittleCorporal generated maldoc process injection 2021-08-11 09:25:23 +02:00
process_creation Merge pull request #1832 from SigmaHQ/rule-devel 2021-08-12 14:28:28 +02:00
raw_access_thread Merging upstream updates 2021-07-01 12:18:30 +05:45
registry_event Merge pull request #1775 from austinsonger/sysmon_disabled_pua_protection_on_microsoft_defender.yml 2021-08-05 15:42:17 +02:00
sysmon fix TargetFilename case error 2021-08-06 08:43:05 +02:00
wmi_event Merging upstream updates 2021-07-01 12:18:30 +05:45