Files
blue-team-tools/rules/windows/sysmon
Tim Burrell (MSTIC) 5051334e85 Sigma queries for
-- terminating threads in a svchost process (InvokePhantom uses this technique to disable windows event logging)
-- GALLIUM threat intel IOCs in recent MSTIC blog/release.
2020-01-02 14:47:55 +00:00
..
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2020-01-02 14:47:55 +00:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00
2019-11-12 23:12:27 +01:00