Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Thomas Patzke
|
765fe9dcd9
|
Further improved Windows user creation rule
* Decreased level
* Fixed field names
* Added false positive possibility
|
2019-04-21 23:54:18 +02:00 |
|
Thomas Patzke
|
80f45349ed
|
Modified rule
* Adjusted ATT&CK tagging
* Set status
|
2019-04-21 00:14:57 +02:00 |
|
patrick
|
8609fc7ece
|
New Sigma rule detecting local user creation
|
2019-04-18 19:59:43 +02:00 |
|