SigmaHQ/rules/windows
2020-05-22 13:28:56 +10:00
..
builtin Update win_susp_ntlm_rdp.yml 2020-05-22 13:28:56 +10:00
malware rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet 2019-10-04 16:17:34 +02:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell powershell false positives 2019-09-06 03:54:19 -04:00
process_creation Revert "Update win_susp_net_execution.yml" 2019-10-25 12:03:23 +11:00
sysmon fix: relevant fields in lsass dll load rule 2019-10-16 19:09:20 +02:00