Andreas Hunkeler
|
7d437c2969
|
Add netsh to renamed binary rule
|
2020-04-20 17:12:25 +02:00 |
|
yugoslavskiy
|
efc404fbae
|
resolve conflicts with rule IDs; restored and deprecated sysmon_mimikatz_detection_lsass.yml
|
2019-11-19 02:11:19 +01:00 |
|
yugoslavskiy
|
cb29628ceb
|
modify rules based on BSI contribution
|
2019-11-14 00:23:16 +03:00 |
|
Thomas Patzke
|
0592cbb67a
|
Added UUIDs to rules
|
2019-11-12 23:12:27 +01:00 |
|
ecco
|
7a1d48cccd
|
fix: PsExec false positives
|
2019-09-26 04:50:43 -04:00 |
|
Thomas Patzke
|
ff7128209e
|
Adjusted level
|
2019-06-20 00:03:48 +02:00 |
|
Thomas Patzke
|
0f8849a652
|
Rule fixes
* tagging
* removed spaces
* converted to generic log source
* typos/case
|
2019-06-20 00:01:56 +02:00 |
|