SigmaHQ/rules/windows
David Vassallo d7443d71a4
Create win_pass_the_hash_2.yml
alternative detection methods
2019-06-14 18:08:36 +03:00
..
builtin Create win_pass_the_hash_2.yml 2019-06-14 18:08:36 +03:00
malware Update win_mal_ursnif.yml 2019-04-14 11:51:13 -05:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell Added missing tags and some minor improvements 2019-03-05 23:25:49 +01:00
process_creation Converted rule to generic log source 2019-06-11 13:20:15 +02:00
sysmon Usage of Channel field name in ELK Windows config 2019-06-11 13:15:43 +02:00