SigmaHQ/rules/network
yugoslavskiy c8ee6e9631
Merge pull request #504 from yugoslavskiy/oscd_ilyas_ochkov
[OSCD] Ilyas Ochkov contribution
2019-11-14 00:22:48 +03:00
..
net_dns_c2_detection.yml add tieto dns exfiltration rules 2019-10-25 04:30:55 +02:00
net_high_dns_bytes_out.yml add tieto dns exfiltration rules 2019-10-25 04:30:55 +02:00
net_high_dns_requests_rate.yml add tieto dns exfiltration rules 2019-10-25 04:30:55 +02:00
net_high_null_records_requests_rate.yml add tieto dns exfiltration rules 2019-10-25 04:30:55 +02:00
net_high_txt_records_requests_rate.yml add tieto dns exfiltration rules 2019-10-25 04:30:55 +02:00
net_mal_dns_cobaltstrike.yml Rule: Cobalt Strike DNS Beaconing 2018-05-10 14:08:52 +02:00
net_possible_dns_rebinding.yml ilyas ochkov contribution 2019-10-29 03:44:22 +03:00
net_susp_dns_b64_queries.yml Rule: Suspicious base64 encoded part of DNS query 2018-05-10 14:08:52 +02:00
net_susp_dns_txt_exec_strings.yml Small rule change 2019-05-09 23:57:55 +02:00
net_susp_network_scan.yml Added field names to first rules 2017-09-12 23:54:04 +02:00
net_susp_telegram_api.yml Rules: Telegram Bot API access 2018-06-05 16:25:43 +02:00