SigmaHQ/rules/windows
Thomas Patzke bdd184a24c
Merge pull request #322 from P4T12ICK/feature/win_user_creation
New Sigma rule detecting local user creation
2019-04-21 00:20:15 +02:00
..
builtin Modified rule 2019-04-21 00:14:57 +02:00
malware Update win_mal_ursnif.yml 2019-04-14 11:51:13 -05:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell Added missing tags and some minor improvements 2019-03-05 23:25:49 +01:00
process_creation Rule: Detect Empire PowerShell Default Cmdline Params 2019-04-20 09:38:41 +02:00
sysmon Merge pull request #309 from jmlynch/master 2019-04-17 23:59:27 +02:00