This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
39dfcd40ec15063c7ec70a99a16f2f058a141e20
blue-team-tools
/
rules
/
windows
T
History
Florian Roth
39dfcd40ec
Merge pull request
#921
from d4rk-d4nph3/master
...
Added support for Defender's PSExec and WMI ASR rules.
2020-09-07 09:40:46 +02:00
..
builtin
fix: FPs with McAfee and CyberReason
2020-09-02 12:30:34 +02:00
deprecated
fix: buggy rule
2020-05-23 18:32:02 +02:00
driver_load
fix: bugfix and cosmetics
2020-06-24 18:10:58 +02:00
file_event
fix ADSI rule false positive
2020-09-06 09:17:53 -04:00
image_load
fix in memory powershell false positive
2020-09-06 09:25:56 -04:00
malware
Further subtechnique updates
2020-06-17 11:31:40 -06:00
network_connection
Updated tags to include sub-techniques
2020-07-18 02:50:57 +01:00
other
Merge pull request
#921
from d4rk-d4nph3/master
2020-09-07 09:40:46 +02:00
powershell
Merge branch 'master' of github.com:Neo23x0/sigma
2020-07-15 10:27:33 -04:00
process_access
Updated invoke_phantom with sub-technique mapping
2020-07-18 02:32:42 +01:00
process_creation
Merge pull request
#977
from barvhaim/patch-1
2020-09-07 09:39:28 +02:00
registry_event
remove false positives in Windows being too broad and add specific keys looked at + add keys from wow64
2020-08-18 05:28:37 -04:00
sysmon
Merge pull request
#928
from duzvik/master
2020-08-12 17:15:27 +02:00