SigmaHQ/rules/windows
Florian Roth eb3a6e86af
Merge pull request #867 from HarishHary/suspicious_powershell_parent_process
New Rule: Suspicious powershell parent process
2020-06-30 10:00:28 +02:00
..
builtin Fix quoting for AD Object WriteDAC Access 2020-06-22 15:31:03 -04:00
deprecated fix: buggy rule 2020-05-23 18:32:02 +02:00
driver_load fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
file_event Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
image_load Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
malware Further subtechnique updates 2020-06-17 11:31:40 -06:00
network_connection Changed category names and remove sysmon log source 2020-06-24 17:41:21 +02:00
other Initial round of subtechnique updates 2020-06-16 14:46:08 -06:00
powershell Added new rule for pwsh_xor_cmd 2020-06-29 22:09:58 +02:00
process_access fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
process_creation Merge pull request #867 from HarishHary/suspicious_powershell_parent_process 2020-06-30 10:00:28 +02:00
registry_event fix: bugfix and cosmetics 2020-06-24 18:10:58 +02:00
sysmon fix: duplicate IDs 2020-06-24 17:04:04 +02:00