This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
01dc930c173e329c191245b76f05de5fa4b5da21
blue-team-tools
/
rules
/
windows
/
create_remote_thread
T
History
frack113
01dc930c17
Change status for old rules
2021-11-27 11:33:14 +01:00
..
sysmon_cactustorch.yml
Remove useless EventID
2021-11-12 11:28:09 +01:00
sysmon_cobaltstrike_process_injection.yml
Fix field name
2021-11-20 19:14:59 +01:00
sysmon_createremotethread_loadlibrary.yml
Change status for old rules
2021-11-27 11:33:14 +01:00
sysmon_password_dumper_lsass.yml
convert to TargetImage|endswith
2021-06-21 20:51:26 +02:00
sysmon_powershell_code_injection.yml
Change status for old rules
2021-11-27 11:33:14 +01:00
sysmon_susp_powershell_rundll32.yml
Remove useless EventID
2021-11-12 11:28:09 +01:00
sysmon_suspicious_remote_thread.yml
fix condition operator case
2021-09-10 13:51:52 +02:00