Florian Roth
|
e91fc4486e
|
refactor: first bigger log source refactoring
see discussion here: https://github.com/SigmaHQ/sigma/discussions/2835
|
2022-03-22 17:58:29 +01:00 |
|
frack113
|
53651cdd2f
|
Add Bits-Client rules
|
2022-03-03 06:27:00 +01:00 |
|
Florian Roth
|
68f0cdf338
|
feat: new log channel windows-codeintegrity-operational
https://twitter.com/SBousseaden/status/1483810148602814466
|
2022-01-20 09:44:36 +01:00 |
|
Florian Roth
|
63f3fd7e73
|
config: add PrintService Operational
|
2021-07-01 09:55:15 +02:00 |
|
Florian Roth
|
a49bfb14dd
|
refactor: Admin log - not Operational
|
2021-06-30 14:22:40 +02:00 |
|
Florian Roth
|
26cfbb9c34
|
config: mapping for Microsoft SMBClient service - security
|
2021-06-30 14:16:26 +02:00 |
|
Florian Roth
|
8262a1d98b
|
config: mappings for Microsoft print service
|
2021-06-30 14:09:44 +02:00 |
|
Florian Roth
|
7d7dd4cb67
|
fix: missing index field in FE helix config
|
2021-03-20 09:09:45 +01:00 |
|
Florian Roth
|
58a1ab9817
|
fix: wrong indentation in fireeye helix mapping
|
2021-03-20 09:04:38 +01:00 |
|
Florian Roth
|
9e287a1b89
|
feat: MSExchange Management log mapping
|
2021-03-20 08:49:59 +01:00 |
|
Alek Rollyson
|
83b8af6cd2
|
Add FirEye Helix backend
|
2020-11-19 11:18:28 -05:00 |
|