frack113
|
da839775fe
|
Update PS rules
|
2021-08-21 09:50:59 +02:00 |
|
frack113
|
f040725dd8
|
fix EventID: 4104 ScriptBlockText
|
2021-08-04 14:49:50 +02:00 |
|
partyh4rd
|
5a98e36905
|
Update powershell_suspicious_getprocess_lsass.yml
fix mitre_code 1552.004 -> 1003.001
|
2021-05-04 14:04:52 +03:00 |
|
Florian Roth
|
1333a95c51
|
rule: get-process lsass
|
2021-04-23 16:44:53 +02:00 |
|