Anton Kutepov
|
98cc025208
|
Renamed ProcessName field to Image for the process_creation category.
|
2021-02-25 01:57:26 +03:00 |
|
Alejandro Ortuno
|
30bd626d76
|
Split command line and do contains all.
|
2020-10-13 10:51:00 +02:00 |
|
Alejandro Ortuno
|
418a9d5a02
|
Use endswith with processname
|
2020-10-11 09:37:08 +02:00 |
|
Alejandro Ortuno
|
748dccc289
|
additional changes to split processname and commandline
|
2020-10-10 13:11:17 +02:00 |
|
Alejandro Ortuno
|
04f415c80b
|
Added the sigma rules per OS
|
2020-10-08 13:23:11 +02:00 |
|