Files
blue-team-tools/rules/windows/process_creation
Nasreddine Bencherchali 04ad307e4e Update proc_creation_win_susp_advancedrun_priv_user.yml
Added cases for LocalService and NetworkService, which could be interesting to monitor:

RunAs=10 (Network Service)
RunAs=11 (Local Service)
2022-05-05 21:06:53 +01:00
..
2022-03-07 17:11:00 +01:00
2022-03-17 16:48:41 +01:00