SigmaHQ/rules/windows
2017-03-14 14:53:03 +01:00
..
builtin Rule: Access to ADMIN$ share 2017-03-14 14:53:03 +01:00
powershell Sysmon as 'service' of product 'windows' 2017-03-13 09:23:08 +01:00
sysmon Rule: Suspicious executions in web folders / non-exe folders 2017-03-13 23:56:06 +01:00