SigmaHQ/rules/windows
Florian Roth ba682c5de6
Merge pull request #863 from qwerty1q2w/feature
add win_not_allowed_rdp_access.yml rule
2020-06-30 10:03:11 +02:00
..
builtin Update win_not_allowed_rdp_access.yml 2020-06-30 10:03:00 +02:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
file_event Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
image_load Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
other FIX: lint error for title 2020-06-28 11:05:19 +02:00
powershell Added new rule for pwsh_xor_cmd 2020-06-29 22:09:58 +02:00
process_access fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
process_creation Merge pull request #867 from HarishHary/suspicious_powershell_parent_process 2020-06-30 10:00:28 +02:00
registry_event fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
sysmon fix: duplicate IDs 2020-06-24 17:04:04 +02:00