Files
blue-team-tools/rules/windows
Nasreddine Bencherchali 04ad307e4e Update proc_creation_win_susp_advancedrun_priv_user.yml
Added cases for LocalService and NetworkService, which could be interesting to monitor:

RunAs=10 (Network Service)
RunAs=11 (Local Service)
2022-05-05 21:06:53 +01:00
..
2022-04-04 10:57:23 +02:00
2022-05-01 11:34:54 +02:00
2022-03-16 13:43:54 +01:00
2022-04-11 11:35:19 +02:00
2022-05-02 16:25:33 +02:00
2022-05-05 17:27:35 +02:00
2022-03-15 18:05:42 +01:00
2022-05-05 07:54:16 +02:00
2022-01-19 18:23:30 +01:00