Yugoslavskiy Daniil
|
5b70cfd3f7
|
review windows/sysmon
|
2020-08-29 02:03:28 +02:00 |
|
Chris O'Brien
|
fe5dbece3d
|
Date typos...more than I thought...
|
2020-04-02 10:00:00 +02:00 |
|
Florian Roth
|
4f3e3166d3
|
fixing false positives
|
2020-02-26 09:33:55 +01:00 |
|
Thomas Patzke
|
9bb50f3d60
|
OSCD QA wave 2
* Improved rules
* Added filtering
* Adjusted severity
|
2020-01-17 15:46:28 +01:00 |
|
Thomas Patzke
|
8d6a507ec4
|
OSCD QA wave 1
* Checked all rules against Mordor and EVTX samples datasets
* Added field names
* Some severity adjustments
* Fixes
|
2020-01-11 00:11:27 +01:00 |
|
Thomas Patzke
|
924e1feb54
|
UUIDs + moved unsupported logic
* Added UUIDs to all contributed rules
* Moved unsupported logic directory out of rules/ because this breaks CI
testing.
|
2019-12-19 23:56:36 +01:00 |
|
Yugoslavskiy Daniil
|
d19df2e4f7
|
fix issues with wrong tagging
|
2019-12-15 00:17:22 +01:00 |
|
yugoslavskiy
|
3cd1abd0a1
|
Update sysmon_suspicious_remote_thread.yml
|
2019-11-14 00:34:09 +03:00 |
|
darkquasar
|
96643b5446
|
New rule Suspicious Remote Thread Created
|
2019-10-28 22:12:57 -07:00 |
|