Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
0806e4ccd28271f628e5579965be1ec6dffbf5ff
blue-team-tools/rules/windows/sysmon
T
History
frack113 e712d9696b Merge pull request #2000 from frack113/split_global
Split frack113 global rules
2021-09-08 06:26:35 +02:00
..
sysmon_abusing_windows_telemetry_for_persistence.yml
Various fixes
2021-09-07 23:38:07 +02:00
sysmon_accessing_winapi_in_powershell_credentials_dumping.yml
Merge branch 'master' into falsepositives_NOT_a_list
2021-05-27 10:23:19 +02:00
sysmon_config_modification_error.yml
Split global rules
2021-09-07 13:30:32 +02:00
sysmon_config_modification_status.yml
Split global rules
2021-09-07 13:30:32 +02:00
sysmon_cve_2021_31979_cve_2021_33771_exploits.yml
Update global ID
2021-09-02 21:16:55 +02:00
sysmon_dcom_iertutil_dll_hijack.yml
Updated rules with modifiers instead of '*' and remove trailing '\\'
2021-06-27 14:51:29 +02:00
sysmon_dns_hybridconnectionmgr_servicebus.yml
Convert eventID 22 to category dns_query
2021-06-10 16:43:33 +02:00
sysmon_pingback_backdoor.yml
update global id
2021-09-02 21:03:25 +02:00
sysmon_wmiprvse_wbemcomn_dll_hijack.yml
Update global ID
2021-09-02 20:07:03 +02:00
Powered by Gitea Version: 1.26.1 Page: 102ms Template: 4ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API