.. |
sysmon_malware_backconnect_ports.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_notepad_network_connection.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_powershell_network_connection.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_rdp_reverse_tunnel.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_regsvr32_network_activity.yml
|
refactor: sysmon rule cleanup > generlization
|
2020-07-01 10:58:39 +02:00 |
sysmon_remote_powershell_session_network.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_rundll32_net_connections.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_susp_prog_location_network_connection.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_susp_rdp.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_suspicious_outbound_kerberos_connection.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_win_binary_github_com.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
sysmon_win_binary_susp_com.yml
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |