SigmaHQ/rules/windows
Furkan ÇALIŞKAN bafd6bde5f
Convert to process_creation
Convert to process_creation
2020-06-04 14:45:10 +03:00
..
builtin Merge pull request #747 from zaphodef/fix/win_susp_backup_delete_source 2020-05-25 10:48:36 +02:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
malware fix: condition location 2020-05-15 12:06:34 +02:00
other fix: converted CRLF line break to LF 2020-03-25 14:36:34 +01:00
powershell Add 'Add-Content' to powershell_ntfs_ads_access 2020-05-13 11:57:10 +02:00
process_creation All Rules use 'TargetFilename' instead of 'TargetFileName'. 2020-06-03 09:00:59 +02:00
sysmon Convert to process_creation 2020-06-04 14:45:10 +03:00