Files
blue-team-tools/rules/windows/process_creation
Thomas Patzke 121e21960e Rule changes
* Replaced variables with usual path names
* Removed Temp directories due to many false positives
* Matching on Image field, CommandLines often contain these paths
2019-05-09 23:09:22 +02:00
..
2019-03-06 00:02:37 +01:00
2019-03-06 06:18:38 +01:00
2019-03-06 00:16:40 +01:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:16:40 +01:00
2019-03-16 00:37:09 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:16:40 +01:00
2019-04-17 23:29:29 +02:00
2019-03-06 05:25:12 +01:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:57:01 +01:00
2019-03-06 00:16:40 +01:00
2019-03-02 00:14:20 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-04-15 08:47:53 +02:00
2019-03-06 05:25:12 +01:00
2019-03-06 00:43:42 +01:00
2019-03-06 00:16:40 +01:00
2019-03-06 05:25:12 +01:00
2019-05-09 23:09:22 +02:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-03-06 05:25:12 +01:00
2019-03-02 00:14:20 +01:00
2019-04-04 22:32:47 +02:00