SigmaHQ/rules/windows
2021-10-14 06:31:36 +01:00
..
builtin fix: prevent FP triggering of other sources utilising ID 1102 2021-10-08 16:43:14 +02:00
create_remote_thread fix condition operator case 2021-09-10 13:51:52 +02:00
create_stream_hash Merging upstream updates 2021-07-01 12:18:30 +05:45
deprecated Clean SyncAppvPublishingServer rules 2021-09-12 07:46:35 +02:00
dns_query split global sysmon_regsvr32_network_activity.yml 2021-09-21 10:33:47 +02:00
driver_load fix field name and date 2021-09-21 19:41:46 +02:00
file_delete Update sysmon_delete_prefetch.yml 2021-09-29 10:58:00 +02:00
file_event Merge pull request #2121 from frack113/update_test 2021-10-06 14:46:48 +02:00
image_load Remove unneeded EventID 2021-10-04 21:25:57 +02:00
malware fix related 2021-09-11 14:22:01 +02:00
network_connection Remove unneeded EventID 2021-10-04 21:25:57 +02:00
other renamed files: lowercase 2021-09-27 22:33:30 +02:00
pipe_created added rule to detect suspicious named pipe connections to an AD FS server 2021-10-08 01:57:22 -04:00
powershell Update powershell_windows_firewall_profile_disabled.yml 2021-10-13 07:01:04 -05:00
process_access Various fixes 2021-09-07 23:38:07 +02:00
process_creation fix yml 2021-10-12 21:02:15 +02:00
raw_access_thread Fix selection with only 1 element 2021-08-14 09:54:27 +02:00
registry_event convert re to endswith 2021-09-24 15:39:56 +02:00
sysmon fix filename 2021-09-22 16:27:05 +02:00
wmi_event fix: tags for WMI / execution / persistence 2021-09-01 16:34:50 +02:00