.. |
sysmon_ads_executable.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_alternate_powershell_hosts_pipe.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_apt_turla_namedpipes.yml
|
fixed various spelling errors all over rules and source code
|
2021-02-24 14:43:13 +00:00 |
sysmon_cactustorch.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_cobaltstrike_process_injection.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_createremotethread_loadlibrary.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_cred_dump_tools_named_pipes.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_mal_namedpipes.yml
|
fixed various spelling errors all over rules and source code
|
2021-02-24 14:43:13 +00:00 |
sysmon_password_dumper_lsass.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_possible_dns_rebinding.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_raw_disk_access_using_illegitimate_tools.yml
|
Rule fixes
|
2020-02-20 23:00:16 +01:00 |
sysmon_susp_powershell_rundll32.yml
|
fixed various spelling errors all over rules and source code
|
2021-02-24 14:43:13 +00:00 |
sysmon_suspicious_remote_thread.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_wmi_event_subscription.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
sysmon_wmi_susp_scripting.yml
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |