Files
blue-team-tools/rules/windows/sysmon
Roberto Rodriguez 87ce07088f Update sysmon_plugx_susp_exe_locations.yml
Duplicate rule title: https://github.com/Neo23x0/sigma/search?q=Executable+used+by+PlugX+in+Uncommon+Location&unscoped_q=Executable+used+by+PlugX+in+Uncommon+Location

This impats Elastalert integration since you cannot have two rules with the same name
2018-12-05 07:58:13 +03:00
..
2018-07-25 07:37:17 +02:00
2018-07-24 07:58:25 +02:00
2018-08-07 08:36:53 +02:00
2018-08-07 08:20:09 +02:00
2018-08-07 08:18:16 +02:00
2018-08-07 08:49:05 +02:00
2018-08-07 08:50:01 +02:00
2018-08-23 08:20:28 +02:00