Files
blue-team-tools/rules
Nate Guagenti 1819e4b02b improve rule
- improve rule logic
- match zeek fields for fields section
- add false positive information
- change rule name to match the logic of the original rule.. Rule said "first" seen, however, no logic that matches that (ie: rare, stacking, etc..)
2021-08-23 14:12:50 -04:00
..
2020-09-13 22:03:04 -06:00
2020-09-15 15:45:33 -06:00
2021-07-01 12:18:30 +05:45
2020-09-13 22:03:04 -06:00
2021-08-23 14:12:50 -04:00
2021-08-18 18:58:20 +00:00