Files
blue-team-tools/rules/windows/process_creation
Steven 05d2de4c26 - Cleaned up some more rules where 'service: sysmon' was combined with category
- Replaced 'service: sysmon' with category: ... for some more events to make the rules more product independent

       modified:   rules/windows/builtin/win_invoke_obfuscation_obfuscated_iex_services.yml
       modified:   rules/windows/malware/mal_azorult_reg.yml
       modified:   rules/windows/powershell/powershell_suspicious_profile_create.yml
       modified:   rules/windows/process_creation/sysmon_cmstp_execution.yml
       modified:   rules/windows/process_creation/win_apt_chafer_mar18.yml
       modified:   rules/windows/process_creation/win_apt_unidentified_nov_18.yml
       modified:   rules/windows/process_creation/win_hktl_createminidump.yml
       modified:   rules/windows/process_creation/win_mal_adwind.yml
       modified:   rules/windows/process_creation/win_silenttrinity_stage_use.yml
2020-10-02 10:45:29 +02:00
..
2020-02-07 15:47:27 +01:00
2020-02-02 12:41:12 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-09-03 09:18:28 +02:00
2019-11-12 23:12:27 +01:00
2020-01-11 00:11:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00
2020-09-26 17:03:29 +02:00
2019-11-12 23:12:27 +01:00
2020-09-13 15:46:45 +02:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-02-20 23:00:16 +01:00
2020-02-02 12:41:12 +01:00