This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
35b027ee1c1599c158cab86dccd090bdafecdf2f
blue-team-tools
/
rules
/
windows
T
History
phantinuss
35b027ee1c
Merge pull request
#4184
from swachchhanda000/master
...
Added new rule that identifies the creation of a scheduled job by usi…
2023-04-21 13:31:22 +02:00
..
builtin
fix: reduce level and gen new uuid
2023-04-17 18:46:15 +02:00
create_remote_thread
feat: new rules, updates and fp fixes (
#4136
)
2023-04-03 12:06:14 +02:00
create_stream_hash
feat: update browsers selections and filters
2023-04-18 18:05:08 +02:00
dns_query
fix: apply suggestions from code review
2023-04-19 15:50:29 +02:00
driver_load
feat: rule updates
2023-04-12 02:57:44 +02:00
file
Merge pull request
#4177
from pH-T/master
2023-04-21 11:24:57 +02:00
image_load
fix: FPs found in different environments
2023-04-20 09:48:47 +02:00
network_connection
remove duplicate references from rule
2023-04-20 10:47:06 -04:00
pipe_created
fix: FPs found in different environments
2023-04-20 09:48:47 +02:00
powershell
Merge pull request
#4189
from tuanhxh1/tuan.le.ncs
2023-04-21 11:42:55 +02:00
process_access
feat: new rules, updates and fp fixes (
#4162
)
2023-04-11 13:04:22 +02:00
process_creation
Merge pull request
#4184
from swachchhanda000/master
2023-04-21 13:31:22 +02:00
raw_access_thread
fix: more fp found in testing
2023-01-18 20:16:34 +01:00
registry
fix: apply suggestions from code review
2023-04-19 15:50:29 +02:00
sysmon
fix: typos in multiple rules (
#4011
)
2023-02-06 13:53:23 +01:00
wmi_event
chore: add nextron authors tag
2023-02-01 11:14:59 +01:00