SigmaHQ/rules/windows
2020-08-24 00:01:50 +00:00
..
builtin Merge pull request #952 from Neo23x0/devel 2020-07-28 10:21:59 +02:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
file_event add wmi persistence script event consumer false positive 2020-07-20 12:27:16 +08:00
image_load Updated tags to include sub-techniques 2020-07-18 02:50:57 +01:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection fix tags for suspicious outbound kerberos activity rule 2020-08-23 21:10:29 +00:00
other Updated to include extra registry key 2020-07-18 02:37:11 +01:00
powershell windows/powershell folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future. 2020-08-24 00:01:50 +00:00
process_access windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future. 2020-08-23 02:03:06 +00:00
process_creation Update win_susp_rasdial_activity.yml 2020-08-18 14:40:37 +02:00
registry_event remove false positives in Windows being too broad and add specific keys looked at + add keys from wow64 2020-08-18 05:28:37 -04:00
sysmon Merge pull request #928 from duzvik/master 2020-08-12 17:15:27 +02:00