This website requires JavaScript.
Explore
Help
Sign In
security-tools
/
blue-team-tools
Watch
1
Star
0
Fork
0
You've already forked blue-team-tools
Code
Issues
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Files
3aa1ad68fbc0540c754bfa123b902ed0af8f25c3
blue-team-tools
/
rules
/
windows
/
process_access
T
History
aw350m3
3aa1ad68fb
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
..
sysmon_cmstp_execution.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
sysmon_cred_dump_lsass_access.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
sysmon_in_memory_assembly_execution.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
sysmon_invoke_phantom.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
sysmon_lsass_memdump.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00
sysmon_malware_verclsid_shellcode.yml
Changed category names and remove sysmon log source
2020-06-24 17:41:21 +02:00
sysmon_mimikatz_trough_winrm.yml
windows/process_access folder reviewed. Old ID’s marked with comment “an old one”. These ID’s have to be removed in future.
2020-08-23 02:03:06 +00:00