Logo
Explore Help
Sign In
security-tools/blue-team-tools
1
0
Fork 0
You've already forked blue-team-tools
Code Issues Pull Requests Actions Packages Projects Releases Wiki Activity
Files
2c4ea3761aac4e8b9968e0fc84f63047215d5b95
blue-team-tools/rules/windows
T
History
Qasim Qlf 2c4ea3761a Update and rename posh_ps_copy_item_system32.yml to posh_ps_copy_item_system_directory.yml
2022-10-20 14:31:48 +05:00
..
builtin
Merge pull request #3602 from nasbench/nasbench-rule-devel
2022-10-20 10:28:56 +02:00
create_remote_thread
fix: filter definition
2022-09-29 14:07:38 +02:00
create_stream_hash
refactor: JuicyPotatoNG imphashes
2022-10-06 08:30:48 +02:00
dns_query
Fix related
2022-10-09 17:28:05 +02:00
driver_load
Update driver_load_vuln_drivers_names.yml
2022-10-17 15:23:14 +02:00
file
New File Access Rules
2022-10-18 11:51:24 +02:00
image_load
fix: FPs on test machine
2022-10-18 16:39:04 +02:00
network_connection
old experimental rule promotion
2022-10-09 16:54:04 +02:00
pipe_created
Fix FP Found In Testing
2022-10-10 17:33:14 +02:00
powershell
Update and rename posh_ps_copy_item_system32.yml to posh_ps_copy_item_system_directory.yml
2022-10-20 14:31:48 +05:00
process_access
fix: FP on test system
2022-10-20 11:08:41 +02:00
process_creation
fix: FP on test system
2022-10-20 11:08:41 +02:00
raw_access_thread
…
registry
fix: FP on test system
2022-10-20 11:08:41 +02:00
sysmon
old experimental rule promotion
2022-10-09 16:54:04 +02:00
wmi_event
old experimental rule promotion
2022-10-09 16:54:04 +02:00
Powered by Gitea Version: 1.26.1 Page: 1450ms Template: 92ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API