Files
blue-team-tools/rules/network
Nate Guagenti 1819e4b02b improve rule
- improve rule logic
- match zeek fields for fields section
- add false positive information
- change rule name to match the logic of the original rule.. Rule said "first" seen, however, no logic that matches that (ie: rare, stacking, etc..)
2021-08-23 14:12:50 -04:00
..
2020-09-15 07:02:30 -06:00
2021-08-23 14:12:50 -04:00
2020-09-15 07:02:30 -06:00
2020-09-15 07:02:30 -06:00
2020-09-15 07:02:30 -06:00
2020-09-15 07:02:30 -06:00
2021-07-11 09:25:33 +02:00
2020-09-15 07:02:30 -06:00