Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
ecco
|
4c54e8322a
|
sysmon eventid 3: filter on outgoing connections (initiated: true) to avoid false positives
|
2019-09-25 11:11:22 -04:00 |
|
Christophe Tafani-Dereeper
|
5bc10a4855
|
Include Github raw URLs in suspicious downloads detection rule
|
2019-07-05 09:01:35 +00:00 |
|
mrblacyk
|
99595a7f89
|
Added missing tags and some minor improvements
|
2019-03-05 23:25:49 +01:00 |
|
Thomas Patzke
|
3ef930b094
|
Escaped '\*' to '\\*' where required
|
2019-02-03 00:24:57 +01:00 |
|
Florian Roth
|
d83f124f5f
|
Rule: Suspicious communication endpoints
|
2018-08-30 10:12:12 +02:00 |
|