Files
blue-team-tools/rules/windows/process_creation
Florian Roth 08883c8e32 refactor: removed old rule that uses Message field
Rules that use the "Message" field are prone to localisation issues and should be avoided whenever possible.

We can build what we call "keyword" rules in these cases and simply combine string values that are searched in the raw data as 1 of them or all of them. (see specs for details)
2021-08-12 09:27:50 +02:00
..
2021-08-07 15:54:43 +02:00
2021-08-06 18:45:38 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-02-07 15:47:27 +01:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-12-08 10:15:30 +01:00
2021-07-07 09:05:00 +02:00
2021-07-01 12:18:30 +05:45
2021-07-31 10:18:21 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-01-11 00:11:27 +01:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-27 10:34:46 +02:00
2020-10-30 13:15:11 +05:30
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2020-02-20 23:00:16 +01:00
2021-07-09 16:41:03 +02:00
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45
2021-07-01 12:18:30 +05:45