Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
Thomas Patzke
|
5f6a4225ec
|
Unified line terminators of rules to Unix
|
2019-11-12 23:05:36 +01:00 |
|
ecco
|
4c54e8322a
|
sysmon eventid 3: filter on outgoing connections (initiated: true) to avoid false positives
|
2019-09-25 11:11:22 -04:00 |
|
Florian Roth
|
f3fb2b41b2
|
Rule: FP filters extended
|
2019-07-23 14:58:36 +02:00 |
|
Michael Wade
|
f70549ec54
|
First Pass
|
2019-06-13 23:15:38 -05:00 |
|
Florian Roth
|
694fa567b6
|
Reformatted
|
2019-05-15 20:22:53 +02:00 |
|
Florian Roth
|
1c36bfde79
|
Bugfix - Swisscom in Newline
|
2019-05-15 15:03:55 +02:00 |
|
Florian Roth
|
d5f49c5777
|
Fixed syntax
|
2019-05-15 14:50:57 +02:00 |
|
Florian Roth
|
508d1cdae0
|
Removed double back slashes
|
2019-05-15 14:46:45 +02:00 |
|
Unknown
|
13522b97a7
|
Adjusting Newline
|
2019-05-15 12:15:41 +02:00 |
|
Unknown
|
275896dbe6
|
Suspicious Outbound RDP Rule likely identifying CVE-2019-0708
|
2019-05-15 11:47:12 +02:00 |
|