Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
052cd2e9677d1d4b87c42db865fb63e8da683ec6
blue-team-tools/rules/windows
T
History
Vadim 052cd2e967 Update proc_creation_win_change_evtx_location.yml
2023-01-03 12:11:13 +03:00
..
builtin
fix: Windows Defender detection
2022-12-28 20:52:53 +01:00
create_remote_thread
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
create_stream_hash
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
dns_query
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
driver_load
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
file
fix: update evtx tamper rules
2023-01-02 15:25:19 +01:00
image_load
Last lolbin (#3845)
2022-12-31 19:53:44 +01:00
network_connection
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
pipe_created
fix: remove unneeded double backslash escape (#3844)
2022-12-31 08:32:46 +01:00
powershell
fix: remove invalid backslash escape
2022-12-31 21:35:07 +09:00
process_access
fix: remove unneeded double backslash escape (#3844)
2022-12-31 08:32:46 +01:00
process_creation
Update proc_creation_win_change_evtx_location.yml
2023-01-03 12:11:13 +03:00
raw_access_thread
feat: enhance duplicate test (#3736)
2022-11-29 13:47:09 +01:00
registry
fix: update evtx tamper rules
2023-01-02 15:25:19 +01:00
sysmon
Refractor (#3794)
2022-12-18 21:00:14 +01:00
wmi_event
Order yaml field
2022-10-25 12:00:56 +02:00
Powered by Gitea Version: 1.26.1 Page: 740ms Template: 24ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API