frack113
|
01dc930c17
|
Change status for old rules
|
2021-11-27 11:33:14 +01:00 |
|
frack113
|
bdb00f403f
|
fix rule
|
2021-11-24 19:24:16 +01:00 |
|
frack113
|
960a03eaf4
|
add lobas Binary
|
2021-11-24 19:17:00 +01:00 |
|
frack113
|
f47d0da3f7
|
add missing MITRE Techniques
|
2021-11-20 12:26:01 +01:00 |
|
Florian Roth
|
c07a9adb9b
|
fix: moved rule written for DNS/Sysmon to the correct folder
|
2021-11-09 17:30:15 +01:00 |
|
Florian Roth
|
39283c0ac2
|
CobaltStrike DNS rules
|
2021-11-09 17:29:43 +01:00 |
|
frack113
|
4c85858e12
|
split global sysmon_regsvr32_network_activity.yml
|
2021-09-21 10:33:47 +02:00 |
|
frack113
|
2a76c469e0
|
normalise name
|
2021-09-11 13:34:19 +02:00 |
|
frack113
|
d9cd1652f2
|
Split global sysmon rules
|
2021-09-09 16:11:41 +02:00 |
|
Thomas Patzke
|
103a8f8052
|
Removed EventID from generic DNS query rule
|
2021-07-08 07:41:11 +02:00 |
|
Florian Roth
|
c0b93a010c
|
NCCGroup rules from rclone blog post
https://research.nccgroup.com/2021/05/27/detecting-rclone-an-effective-tool-for-exfiltration/
|
2021-05-27 12:49:40 +02:00 |
|
Steven
|
0c9a82af89
|
- Remove 'service: sysmon' since defining the categories made the rules generic
|
2020-10-02 09:37:52 +02:00 |
|
Steven
|
8b74abe0bc
|
- Created new categories for sysmon events
- Replaced the explicit EventIDs with the reference to the category
- Moved the rules to the corresponding directories
|
2020-09-30 20:44:14 +02:00 |
|