SigmaHQ/rules/windows
yugoslavskiy c7e9522f29
Merge pull request #1077 from uchakin/oscd
[OSCD] UAC bypass added
2021-01-05 23:06:24 +03:00
..
builtin Merge pull request #1069 from nsaddler/oscd3 2021-01-05 22:58:21 +03:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load Update sysmon_susp_driver_load.yml 2020-11-19 22:56:34 -03:00
file_event Remove additional backslash 2020-11-19 23:04:26 -03:00
image_load Merge pull request #1077 from uchakin/oscd 2021-01-05 23:06:24 +03:00
malware Remove additional backslash 2020-11-19 23:15:38 -03:00
network_connection Remove additional backslash 2020-11-20 00:53:13 -03:00
other Update win_wmi_persistence.yml 2020-11-20 00:58:49 -03:00
powershell Update powershell_shellcode_b64.yml 2020-12-01 02:24:35 +01:00
process_access Merge pull request #1077 from uchakin/oscd 2021-01-05 23:06:24 +03:00
process_creation Merge pull request #1047 from grikos/sigma/oscd 2021-01-05 23:00:20 +03:00
registry_event Merge pull request #1077 from uchakin/oscd 2021-01-05 23:06:24 +03:00
sysmon Merge branch 'oscd' into oscd_rules_improvement 2020-11-28 14:52:31 -03:00