Files
blue-team-tools/rules
Sander Wiebing b8ee736f44 Remove AppData folder as suspicious folder
A lot of software is using the AppData folder for startup keys. Some examples:
- Microsoft Teams (\AppData\Local\Microsoft\Teams)
- Resilio (\AppData\Roaming\Resilio Sync\)
- Discord ( (\AppData\Local\Discord\)
- Spotify ( (\AppData\Roaming\Spotify\)

Too many to whitelist them all
2020-05-24 15:16:07 +02:00
..
2020-05-14 15:53:09 +02:00
2020-05-05 11:32:18 +01:00
2019-11-12 23:12:27 +01:00
2020-02-02 12:41:12 +01:00
2020-05-19 05:13:48 -04:00
2020-05-23 17:38:10 +02:00