SigmaHQ/rules/windows
2021-08-06 18:41:14 +02:00
..
builtin Fix quoting for AD Object WriteDAC Access 2020-06-22 15:31:03 -04:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
file_event Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
image_load Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
other Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
process_access fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
process_creation '--start-with-win' is pretty specific 2021-08-06 18:41:14 +02:00
registry_event fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
sysmon fix: duplicate IDs 2020-06-24 17:04:04 +02:00