SigmaHQ/rules-unsupported
2021-09-20 22:56:13 +02:00
..
driver_load_invoke_obfuscation_clip+_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_obfuscated_iex_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_stdin+_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_var+_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:56:13 +02:00
driver_load_invoke_obfuscation_via_compress_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_rundll_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_stdin_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_use_clip_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_use_mshta_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_use_rundll32_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
driver_load_invoke_obfuscation_via_var++_services.yml split global win_invoke_obfuscation_* 2021-09-20 22:42:59 +02:00
net_dns_high_subdomain_rate.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
net_dns_large_domain_name.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
net_possible_dns_rebinding.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
sysmon_always_install_elevated_msi_spawned_cmd_and_powershell_spawned_processes.yml Add yamllint to GHA 2021-07-26 21:26:16 -04:00
sysmon_always_install_elevated_parent_child_correlated.yml Add yamllint to GHA 2021-07-26 21:26:16 -04:00
sysmon_process_reimaging.yml All Rules use 'TargetFilename' instead of 'TargetFileName'. 2020-06-03 09:00:59 +02:00
win_access_fake_files_with_stored_credentials.yml Replace start of paths with placeholders 2020-10-17 09:36:25 -04:00
win_dumping_ntdsdit_via_dcsync.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
win_dumping_ntdsdit_via_netsync.yml UUIDs + moved unsupported logic 2019-12-19 23:56:36 +01:00
win_kernel_and_3rd_party_drivers_exploits_token_stealing.yml Add yamllint to GHA 2021-07-26 21:26:16 -04:00
win_possible_privilege_escalation_using_rotten_potato.yml Add yamllint to GHA 2021-07-26 21:26:16 -04:00
win_remote_schtask.yml Added selection criteria + moved to Unsupported rule 2020-10-11 12:48:48 +10:30
win_remote_service.yml Added conditional description + moved to unsupported-rules 2020-10-11 12:40:24 +10:30