mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 01:45:21 +00:00
e4d764ceba
Rule to detects the attack technique pass the hash which is used to move laterally inside the network |
||
---|---|---|
.. | ||
win_alert_mimikatz_keywords.yml | ||
win_av_relevant_match.yml | ||
win_malicious_service_install.yml | ||
win_pass_the_hash.yml | ||
win_susp_add_sid_history.yml | ||
win_susp_dsrm_password_change.yml | ||
win_susp_eventlog_cleared.yml | ||
win_susp_failed_logon_reasons.yml | ||
win_susp_failed_logons_single_source.yml | ||
win_susp_kerberos_manipulation.yml | ||
win_susp_lsass_dump.yml | ||
win_susp_rc4_kerberos.yml | ||
win_susp_recon_activity.yml | ||
win_susp_security_eventlog_cleared.yml |