Files
blue-team-tools/rules
Nasreddine Bencherchali 40ccd91a94 Update proc_creation_win_msdt_diagcab.yml
In my testing i found that ".diagcab" extension is not required. You can use .txt with the /cab flag and it'll spawn an msdt process.

Also I added the "-" (dash) version of the flag
2022-06-21 11:45:53 +01:00
..
2022-01-19 18:23:30 +01:00
2022-06-03 15:35:24 +02:00
2022-06-07 17:09:06 +02:00