Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
17aaf7fdcdc77af2b2af1c6fe3390c8be4aed913
blue-team-tools/rules/windows
T
History
Nasreddine Bencherchali 17aaf7fdcd Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
fix: FPs noticed with Aurora
2023-01-09 10:39:54 +01:00
..
builtin
Filename normalisation
2023-01-07 08:52:11 +01:00
create_remote_thread
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
create_stream_hash
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
dns_query
Promotion rules (#3821)
2022-12-27 12:29:10 +01:00
driver_load
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
file
fix: multiple issues
2023-01-06 18:04:04 +01:00
image_load
fix: multiple issues
2023-01-06 18:04:04 +01:00
network_connection
Fix invalid field cast or name (#3841)
2022-12-30 11:46:21 +01:00
pipe_created
fix: remove unneeded double backslash escape (#3844)
2022-12-31 08:32:46 +01:00
powershell
Merge branch 'master' into rule-devel
2023-01-09 09:56:21 +01:00
process_access
Update proc_access_win_invoke_patchingapi.yml
2023-01-07 13:04:57 +01:00
process_creation
Merge pull request #3888 from SigmaHQ/aurora-false-positive-fixing
2023-01-09 10:39:54 +01:00
raw_access_thread
feat: enhance duplicate test (#3736)
2022-11-29 13:47:09 +01:00
registry
fix: separate selection and add missing modified
2023-01-06 17:41:01 +01:00
sysmon
fix: update modified date
2023-01-03 10:37:09 +01:00
wmi_event
Order yaml field
2022-10-25 12:00:56 +02:00
Powered by Gitea Version: 1.26.1 Page: 47ms Template: 17ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API