Wagga
|
6c42bfb64b
|
Update file_event_win_powershell_startup_shortcuts.yml
|
2022-08-29 20:15:54 +02:00 |
|
Wagga
|
8dbeedf728
|
Update file_event_win_powershell_startup_shortcuts.yml
|
2022-08-29 20:14:47 +02:00 |
|
Wagga
|
691aae2638
|
Update proc_creation_win_ntfs_short_name_path_use_image.yml
|
2022-08-29 20:13:14 +02:00 |
|
Wagga
|
a693e181ff
|
Update registry_set_disable_uac_registry.yml
|
2022-08-29 20:12:10 +02:00 |
|
Wagga
|
277032b460
|
Update registry_set_mpnotify_persistence.yml
|
2022-08-29 20:11:29 +02:00 |
|
Wagga
|
63ea4d7fb6
|
Update registry_set_fax_dll_persistance.yml
|
2022-08-29 20:10:25 +02:00 |
|
Wagga
|
cb4f834845
|
Update posh_ps_nishang_malicious_commandlets.yml
Typo in detection : https://github.com/samratashok/nishang/blob/master/Utility/Add-Persistence.ps1
|
2022-08-29 18:53:22 +02:00 |
|
Wagga
|
8a9d63bba1
|
Update proc_creation_win_wmic_remote_service.yml
|
2022-08-29 18:50:04 +02:00 |
|
Wagga
|
86b448b715
|
Update proc_creation_win_lolbin_register_app.yml
|
2022-08-29 18:49:17 +02:00 |
|
Wagga
|
351d8bcc40
|
Update proc_creation_win_wmic_unquoted_service_search.yml
|
2022-08-29 18:48:29 +02:00 |
|
Wagga
|
7c0bd62e9f
|
Update proc_creation_win_cmd_redirection_susp_folder.yml
|
2022-08-29 18:47:44 +02:00 |
|
Wagga
|
6494e185cf
|
Update image_load_vmware_xfer_load_dll_from_nondefault_path.yml
|
2022-08-29 18:46:34 +02:00 |
|
Wagga
|
eb572e8b0c
|
Update proc_creation_win_wpbbin_persistence.yml
|
2022-08-29 18:45:49 +02:00 |
|
Wagga
|
86876adad4
|
Update proc_creation_win_cmd_dosfuscation.yml
|
2022-08-29 18:45:00 +02:00 |
|
Wagga
|
7b0eb71563
|
Update proc_creation_win_vmtoolsd_susp_child_process.yml
|
2022-08-29 18:44:19 +02:00 |
|
Wagga
|
0d92b047ff
|
Update proc_creation_win_susp_powershell_webclient_casing.yml
|
2022-08-29 12:11:33 +02:00 |
|
Wagga
|
7c6bf47757
|
Update proc_creation_win_susp_rundll32_user32_dll.yml
|
2022-08-29 07:59:45 +02:00 |
|
Wagga
|
39edfddce4
|
Update proc_creation_win_lolbin_diantz_ads.yml
|
2022-08-29 07:58:05 +02:00 |
|
Wagga
|
9d3d718c27
|
Update proc_creation_win_icacls_deny.yml
|
2022-08-29 07:57:34 +02:00 |
|
Wagga
|
d5724fb583
|
Update proc_creation_win_susp_advancedrun.yml
|
2022-08-29 07:56:59 +02:00 |
|
Wagga
|
11e24a6e66
|
Update proc_creation_win_susp_advancedrun_priv_user.yml
|
2022-08-29 07:56:27 +02:00 |
|
Wagga
|
cffc6fa947
|
Update proc_creation_win_susp_nmap.yml
|
2022-08-29 07:55:38 +02:00 |
|
Wagga
|
5515dc7397
|
Update proc_creation_win_fsutil_drive_enumeration.yml
|
2022-08-29 07:54:56 +02:00 |
|
Wagga
|
da82c739c5
|
Update proc_creation_win_attrib_system_susp_paths.yml
|
2022-08-29 07:54:18 +02:00 |
|
Wagga
|
c0b3cd847f
|
Update proc_creation_win_lolbin_cl_mutexverifiers.yml
|
2022-08-29 07:53:15 +02:00 |
|
Wagga
|
37230eabee
|
Update proc_creation_win_lolbin_cl_loadassembly.yml
|
2022-08-29 07:52:56 +02:00 |
|
Wagga
|
762ac06eea
|
Update proc_creation_win_lolbin_wlrmdr.yml
|
2022-08-29 07:52:12 +02:00 |
|
Wagga
|
b0af5fbc8f
|
Update proc_creation_win_lolbin_squirrel.yml
|
2022-08-29 07:50:55 +02:00 |
|
Wagga
|
ec268e0983
|
Update registry_set_persistence_autodial_dll.yml
|
2022-08-29 07:48:27 +02:00 |
|
Wagga
|
3f3705164f
|
Update proc_creation_win_net_user_add_never_expire.yml
|
2022-08-29 07:47:56 +02:00 |
|
Wagga
|
1a26c174f2
|
Update proc_creation_win_inline_base64_mz_header.yml
|
2022-08-29 07:47:27 +02:00 |
|
Wagga
|
c820429bdb
|
Update proc_creation_win_windows_terminal_susp_children.yml
|
2022-08-29 07:46:30 +02:00 |
|
Wagga
|
57fcc2864f
|
Update posh_ps_invoke_dnsexfiltration.yml
|
2022-08-29 07:44:46 +02:00 |
|
Wagga
|
8594d926b1
|
Update proc_creation_win_set_policies_to_unsecure_level.yml
|
2022-08-29 07:43:52 +02:00 |
|
Wagga
|
ef0aae28be
|
Update posh_ps_set_policies_to_unsecure_level.yml
|
2022-08-29 07:43:02 +02:00 |
|
Wagga
|
8235eec297
|
Update posh_ps_susp_write_eventlog.yml
|
2022-08-29 07:39:53 +02:00 |
|
Wagga
|
f73e1c9b36
|
Update win_system_application_sysmon_crash.yml
|
2022-08-29 07:37:40 +02:00 |
|
Wagga
|
560bd7848e
|
Update win_service_install_pdqdeploy_runner.yml
|
2022-08-29 07:31:18 +02:00 |
|
Wagga
|
2e1467aa59
|
Update win_mssql_disable_audit_settings.yml
|
2022-08-29 07:29:50 +02:00 |
|
Wagga
|
dc9f4fbb49
|
Update image_load_defender_load_dll_from_nondefault_path.yml
|
2022-08-29 07:28:07 +02:00 |
|
Wagga
|
d8852f6fa6
|
Update proc_creation_win_dll_sideload_vmware_xfer.yml
|
2022-08-29 07:27:21 +02:00 |
|
Wagga
|
f5a0c0e012
|
Update proc_creation_win_lolbin_winword.yml
|
2022-08-29 07:26:44 +02:00 |
|
Wagga
|
c8a5414412
|
Update proc_creation_win_dll_sideload_defender.yml
|
2022-08-29 07:26:03 +02:00 |
|
Wagga
|
f85cd9040d
|
Update win_security_mitigations_defender_load_unsigned_dll.yml
|
2022-08-29 07:24:32 +02:00 |
|
Wagga
|
8f84d10855
|
Update net_connection_win_excel_outbound_network_connection.yml
|
2022-08-29 07:21:47 +02:00 |
|
Florian Roth
|
00305d6727
|
Merge pull request #3438 from frack113/redcannary_20220828
Redcannary 20220828
|
2022-08-28 19:53:08 +02:00 |
|
Florian Roth
|
ff88a7e177
|
fix: FP with VSCode extensions
|
2022-08-28 19:33:49 +02:00 |
|
Florian Roth
|
a49e2fe1ee
|
refactor: add IPv6 addresses
|
2022-08-28 19:31:14 +02:00 |
|
Florian Roth
|
6fc281d1d6
|
some more
|
2022-08-28 18:59:34 +02:00 |
|
frack113
|
600500d963
|
fix space
|
2022-08-28 12:17:36 +02:00 |
|