This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
19396788dbedc57249a46efed2bb1927abc376d4
blue-team-tools
/
rules
/
windows
T
History
Nasreddine Bencherchali
19396788db
Merge pull request
#3831
from redsand/fp_suspicious_process_privilege
...
FP: filters out erl.exe running handle.exe with elevated privileges
2022-12-28 21:18:54 +01:00
..
builtin
fix: Windows Defender detection
2022-12-28 20:52:53 +01:00
create_remote_thread
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
create_stream_hash
Merge pull request
#3757
from SigmaHQ/aurora-false-positive-fixing
2022-12-05 18:54:31 +01:00
dns_query
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
driver_load
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
file
fix: rename links from old repo to SigmaHQ
2022-12-27 21:05:16 +01:00
image_load
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
network_connection
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
pipe_created
fix: rename links from old repo to SigmaHQ
2022-12-27 21:05:16 +01:00
powershell
Merge pull request
#3826
from nasbench/fix-old-sigma-link
2022-12-28 11:11:04 +01:00
process_access
Merge branch 'master' into aurora-false-positive-fixing
2022-12-28 13:28:56 +01:00
process_creation
Merge pull request
#3831
from redsand/fp_suspicious_process_privilege
2022-12-28 21:18:54 +01:00
raw_access_thread
feat: enhance duplicate test (
#3736
)
2022-11-29 13:47:09 +01:00
registry
Promotion rules (
#3821
)
2022-12-27 12:29:10 +01:00
sysmon
Refractor (
#3794
)
2022-12-18 21:00:14 +01:00
wmi_event
Order yaml field
2022-10-25 12:00:56 +02:00