SigmaHQ/rules/windows/other
yugoslavskiy 5ade9208d5
Merge pull request #1166 from drdoc/oscd
[OSCD] Possible Zerologon (CVE-2020-1472) exploitation using well-known tools
2021-01-06 00:12:34 +03:00
..
win_defender_amsi_trigger.yml Windows Defender AMSI Trigger Detected 2020-09-14 18:10:38 +05:45
win_defender_bypass.yml att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
win_defender_disabled.yml att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
win_defender_psexec_wmi_asr.yml fix typos, update tags 2020-09-13 15:46:45 +02:00
win_defender_threat.yml FIX: lint error for title 2020-06-28 11:05:19 +02:00
win_pcap_drivers.yml Fix 2020-10-15 20:29:02 -03:00
win_possible_zerologon_exploitation_using_wellknown_tools.yml update syntax a bit to re-run the test 2020-10-20 17:40:53 +02:00
win_rare_schtask_creation.yml att&ck tags review: windows/builtin, windows/driver_load, windows/file_event, windows/image_load, windows/other 2020-08-25 01:09:17 +02:00
win_tool_psexec.yml Update win_tool_psexec.yml 2020-11-20 00:57:16 -03:00
win_wmi_persistence.yml Update win_wmi_persistence.yml 2020-11-20 00:58:49 -03:00