SigmaHQ/rules/windows
2019-11-04 20:36:21 +03:00
..
builtin rule: mimikatz use extended 2019-10-11 18:50:33 +02:00
malware rules: AV rules updated to reflect 1.7.2 auf AV cheat sheet 2019-10-04 16:17:34 +02:00
other Converted to use the new process_creation data source 2019-03-09 20:57:59 +03:00
powershell powershell false positives 2019-09-06 03:54:19 -04:00
process_creation Rename win_susp_msoffice.yml to process_creation_susp_msoffice.yml 2019-11-04 20:36:21 +03:00
sysmon Update sysmon_webshell_creation_detect.yml 2019-11-04 19:23:52 +03:00