Commit Graph

9 Commits

Author SHA1 Message Date
Florian Roth
4a4a94fc9c Rules prone to false positives on process memory to "file" only 2018-06-13 08:30:02 +02:00
Florian Roth
70037ba67e PowerShell JAB rule 2018-04-14 11:56:12 +02:00
Florian Roth
da310446fe Generic PowerShell rule for code the uses Kernel32 / write remote process memory 2018-04-06 12:45:37 +02:00
Florian Roth
e71703c8d0 WScript PowerShell Combo 2018-02-08 23:03:23 +01:00
Florian Roth
1d8093a9de New suspicious PowerShell scripts 2017-10-01 00:24:31 +02:00
Florian Roth
ca2c820f5c Powershell in Word Doc 2017-07-01 14:35:23 +02:00
Florian Roth
32ec315e97 False Positive Reduction 2017-06-08 17:08:04 +02:00
Florian Roth
a564860d0a PowerShell Rule Bugfix 2017-02-23 17:42:26 +01:00
Florian Roth
8dc9ba46d5 Suspicious PowerShell Code 2017-02-23 17:13:04 +01:00