Files
blue-team-tools/tools/sigma
albchen 1dec1a49fa Mapped OriginalFileName in DeviceProcessEvents
Mapped OriginalFileName to ProcessVersionInfoOriginalFileName in DeviceProcessEvents. Tested and works for rules such as https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/win_renamed_binary.yml
2021-09-10 15:51:32 -07:00
..
2021-08-18 19:00:57 +00:00
2019-11-11 23:35:16 +01:00
2021-08-22 08:57:07 +02:00
2021-09-05 17:50:54 +02:00
2021-08-18 19:00:57 +00:00
2021-08-18 19:00:57 +00:00
2020-06-06 01:03:02 +02:00