Florian Roth
|
c8b3036949
|
Merge pull request #1968 from SigmaHQ/rule-devel
docs: note to improved sysmon config
|
2021-09-01 13:21:28 +02:00 |
|
Florian Roth
|
f102b2d9a1
|
docs: note to improved sysmon config
|
2021-09-01 13:07:18 +02:00 |
|
phantinuss
|
e59b8e1e3e
|
add applicable pipe names from regex rule
|
2021-08-26 14:53:20 +02:00 |
|
phantinuss
|
dc19268583
|
remove becasue of possible conflict
with a legitimate tool (https://labs.nettitude.com/blog/cve-2017-16245-cve-2017-16246-avecto-defendpoint-multiple-vulnerabilities/)
|
2021-08-26 14:25:12 +02:00 |
|
Florian Roth
|
6c7d355ef5
|
Try to add more pipe names to this non-regex rule
|
2021-08-26 14:00:57 +02:00 |
|
phantinuss
|
217dbc768a
|
More malleable CobaltStrike C2 profiles from new source/reference
|
2021-08-26 12:53:43 +02:00 |
|
Florian Roth
|
096395a49a
|
fix: one condition style error
|
2021-07-30 07:19:42 +02:00 |
|
Florian Roth
|
0cbb6f82ad
|
CobaltStrike NamedPipe Patterns
https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575
|
2021-07-30 07:11:11 +02:00 |
|