SigmaHQ/rules/windows
2020-05-15 12:35:32 -04:00
..
builtin remove false positives with cmd as child of services.exe (not specifically related to meterpreter/cobaltstrike) 2020-05-15 04:45:25 -04:00
deprecated Merge branch 'master' into oscd 2020-02-03 23:13:16 +01:00
malware Changed level to ciritcal 2020-05-11 10:40:23 +02:00
other fix: converted CRLF line break to LF 2020-03-25 14:36:34 +01:00
powershell fix incorrect use of action global 2020-05-06 22:53:02 +02:00
process_creation standardize rules with Image and CommandLine instead of NewProcessName and ProcessCommandLine 2020-05-15 12:35:32 -04:00
sysmon Merge branch 'master' into rule-devel 2020-05-16 08:59:34 +02:00