Commit Graph

7964 Commits

Author SHA1 Message Date
Jonhnathan 22e5f83a6c Update sysmon_dllhost_net_connections.yml 2020-10-15 16:19:43 -03:00
Jonhnathan acfe0633e2 Update win_mal_ursnif.yml 2020-10-15 16:18:38 -03:00
Jonhnathan 983e9cb9ae Update win_mal_ryuk.yml 2020-10-15 16:18:14 -03:00
Jonhnathan 8d44548a2c Update win_mal_flowcloud.yml 2020-10-15 16:16:08 -03:00
Jonhnathan ef646e74d8 Update mal_azorult_reg.yml 2020-10-15 16:15:25 -03:00
Jonhnathan 69c90570ec Update av_webshell.yml 2020-10-15 16:14:08 -03:00
Jonhnathan cdaa5ef3a6 Update av_relevant_files.yml 2020-10-15 16:13:22 -03:00
Jonhnathan 7dc720cf13 Update av_password_dumper.yml 2020-10-15 16:11:52 -03:00
Jonhnathan dea145cd5e Update av_exploiting.yml 2020-10-15 16:11:24 -03:00
Jonhnathan 7adfd75c0a Update sysmon_svchost_dll_search_order_hijack.yml 2020-10-15 16:10:23 -03:00
Jonhnathan b6cf10fdd2 Update sysmon_susp_winword_wmidll_load.yml 2020-10-15 16:09:44 -03:00
Jonhnathan efe5ad92c3 Update sysmon_susp_winword_vbadll_load.yml 2020-10-15 16:09:21 -03:00
Jonhnathan 7c196aed22 Update sysmon_susp_office_kerberos_dll_load.yml 2020-10-15 16:09:03 -03:00
Jonhnathan 38ef5976dc Update sysmon_susp_office_dsparse_dll_load.yml 2020-10-15 16:08:55 -03:00
Jonhnathan 8aa2f8582b Update sysmon_susp_office_dsparse_dll_load.yml 2020-10-15 16:07:46 -03:00
Jonhnathan 4de241d44c Update sysmon_susp_office_dotnet_gac_dll_load.yml 2020-10-15 16:07:10 -03:00
Jonhnathan ecbec06709 Update sysmon_susp_office_dotnet_clr_dll_load.yml 2020-10-15 16:06:47 -03:00
Jonhnathan 0d4f372351 Update sysmon_susp_office_dotnet_assembly_dll_load.yml 2020-10-15 16:06:21 -03:00
Jonhnathan 1136725728 Update sysmon_susp_image_load.yml 2020-10-15 16:05:50 -03:00
Jonhnathan 56594a5a06 Update sysmon_mimikatz_inmemory_detection.yml 2020-10-15 16:05:11 -03:00
Jonhnathan 569f14eb1e Update sysmon_tsclient_filewrite_startup.yml 2020-10-15 16:02:52 -03:00
Jonhnathan 7d5e404b32 Update sysmon_susp_procexplorer_driver_created_in_tmp_folder.yml 2020-10-15 16:02:16 -03:00
Jonhnathan 5790cc2ea7 Update sysmon_susp_adsi_cache_usage.yml 2020-10-15 16:01:46 -03:00
Jonhnathan 9eedeabda9 Update sysmon_quarkspw_filedump.yml 2020-10-15 16:01:24 -03:00
Jonhnathan d2d49c445a Update sysmon_powershell_exploit_scripts.yml 2020-10-15 16:00:20 -03:00
Jonhnathan b6b34b37d9 Update sysmon_ghostpack_safetykatz.yml 2020-10-15 15:59:09 -03:00
Jonhnathan 099843470e Update sysmon_creation_system_file.yml 2020-10-15 15:58:10 -03:00
Jonhnathan 427962937b Update sysmon_susp_driver_load.yml 2020-10-15 15:57:05 -03:00
Jonhnathan 1cd56f5dae Update win_vul_cve_2020_0688.yml 2020-10-15 15:56:36 -03:00
Jonhnathan ef3af551e9 Update win_user_driver_loaded.yml 2020-10-15 15:56:16 -03:00
Jonhnathan 4e70b2d797 Update win_user_added_to_local_administrators.yml 2020-10-15 15:55:21 -03:00
Jonhnathan c0892c63c8 Update win_svcctl_remote_service.yml 2020-10-15 15:54:47 -03:00
Jonhnathan d96bd0d9f3 Update win_susp_wmi_login.yml 2020-10-15 15:54:21 -03:00
Jonhnathan 496cfcb26a Update win_susp_sdelete.yml 2020-10-15 15:53:51 -03:00
Jonhnathan 600c7057b1 Update win_susp_sam_dump.yml 2020-10-15 15:53:26 -03:00
Jonhnathan 754e67c0d9 Update win_susp_rc4_kerberos.yml 2020-10-15 15:52:48 -03:00
Jonhnathan 43a56b6759 Update win_susp_raccess_sensitive_fext.yml 2020-10-15 15:51:57 -03:00
Jonhnathan 054255fb17 Update win_susp_psexec.yml 2020-10-15 15:51:16 -03:00
Jonhnathan dae1f3fa71 Update win_susp_ntlm_rdp.yml 2020-10-15 15:50:44 -03:00
Jonhnathan 9b8817f489 Update win_susp_msmpeng_crash.yml 2020-10-15 15:50:01 -03:00
Jonhnathan c310d72e2b Update win_susp_mshta_execution.yml 2020-10-15 15:49:39 -03:00
Jonhnathan 7419396351 Update win_susp_mshta_execution.yml 2020-10-15 15:49:26 -03:00
Jonhnathan 1eb0ccbf14 Update win_susp_local_anon_logon_created.yml 2020-10-15 15:48:36 -03:00
Jonhnathan e089118718 Update win_possible_dc_shadow.yml 2020-10-15 15:45:55 -03:00
Jonhnathan 6961ee4986 Update win_net_ntlm_downgrade.yml 2020-10-15 15:44:24 -03:00
Jonhnathan 8261737728 Update win_mmc20_lateral_movement.yml 2020-10-15 15:42:07 -03:00
Jonhnathan 8f3542a73e Update win_mal_wceaux_dll.yml 2020-10-15 15:41:13 -03:00
Vasiliy Burov b10332dde8 Update powershell_cmdline_special_characters.yml 2020-10-15 21:31:24 +03:00
Jonhnathan 9bfd63ec26 Update win_hack_smbexec.yml 2020-10-15 15:20:08 -03:00
Jonhnathan e5789a2a52 Update win_dcsync.yml 2020-10-15 15:19:18 -03:00