frack113
|
768855e6d6
|
update modified after FP fix
|
2021-08-18 18:17:53 +02:00 |
|
Florian Roth
|
44013e25c8
|
fix: FPs with WMIADAP.exe
|
2021-08-18 17:26:57 +02:00 |
|
mlp1515
|
b4883701b4
|
Update sysmon_wmi_module_load.yml
|
2021-06-15 16:16:28 +02:00 |
|
Jonhnathan
|
627a83914a
|
Update Threat Hunter Playbook Reference
|
2021-05-22 01:01:33 -03:00 |
|
ecco
|
e30eaa0202
|
be more specific about file location
|
2020-07-09 13:33:59 -04:00 |
|
ecco
|
94e3bd9e6b
|
add WMI module load false positive
|
2020-07-09 13:32:21 -04:00 |
|
ecco
|
905f1b3823
|
add WMI and powershell false positives
|
2020-07-09 10:26:54 -04:00 |
|
Florian Roth
|
f3fedef8f5
|
Changed category names and remove sysmon log source
|
2020-06-24 17:41:21 +02:00 |
|